CVE-2025-22927

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 21, 2025
CWE ID 22

Summary

CVE-2025-22927 represents a vulnerability in OS4ED openSIS versions 8.0 to 9.1. This issue permits attackers to execute directory traversal attacks by crafting malicious POST requests to the /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename endpoint. Successful exploitation could result in unauthorized access to sensitive information or system compromise. Attackers can manipulate the filename parameter to trick the application into reading and executing files outside of the intended directory, leading to potential security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share