Content Spoofing Vulnerability in RosarioSIS Student Information System - Astra Security Blog

Product Name: RosarioSIS Student Information System

Vulnerability: Content Spoofing

Vulnerable Version: v12.0.0

CVE: CVE-2025-29621

The researchers from Astra’s security team, on March 4, 2025, discovered a content spoofing vulnerability in the Demo Web Application. This issue was identified in the “Theme” configuration under “My Preferences,” where improper user input validation allowed attackers to manipulate application settings.

A content spoofing vulnerability occurs when an application fails to validate and sanitize user input, allowing attackers to alter displayed content, leading to user interface disruptions or security risks.

Technical Breakdown

How was it discovered?

The vulnerability was identified when security researchers analyzed the “Theme” configuration settings in the Demo Web Application. During testing, it was observed that improper input validation allowed modification of the values[Preferences][THEME] parameter, leading to UI failures and rendering issues. This discovery highlighted a lack of input sanitization, making the application susceptible to further exploitation.

How do we recreate this vulnerability?

The issue is exploited as follows:

  1. The user logs into the Demo Web Application.
  2. Under the “Users” option, the “My Preferences” section is accessed.
  3. A theme selection is made under “Display Options,” and the settings are saved.
  4. The HTTP request containing the values[Preferences][THEME] parameter is intercepted via Burp Suite.
  5. The value is modified from “FlatSIS” to an arbitrary string like “111111” and forwarded.
  6. The application processes the invalid input, leading to UI failures and unexpected behavior.

Impact of Content Spoofing Vulnerability

The severity of this vulnerability ranges from moderate to high, depending on the exploitation method. Potential impacts include:

Current Status

The vulnerability was discovered in the “Display Options” section within the “My Preferences” page of the RosarioSIS Student Information System v12.0.0. The issue has been reported, and developers are advised to implement remediation measures to address the risk.

What Can You Do?

To avoid potential exploitation, users are strongly advised to update RosarioSIS to the latest version, which includes essential security patches.

Prateek Kuber

Prateek is a cybersecurity professional with a strong interest in coding and a knack for crafting detailed, informative articles. Outside the world of cybersecurity, he enjoys a weekly game of football and something to binge watch!