CVE-2025-22927
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 21, 2025
CWE ID 22
Summary
CVE-2025-22927 represents a vulnerability in OS4ED openSIS versions 8.0 to 9.1. This issue permits attackers to execute directory traversal attacks by crafting malicious POST requests to the /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename endpoint. Successful exploitation could result in unauthorized access to sensitive information or system compromise. Attackers can manipulate the filename parameter to trick the application into reading and executing files outside of the intended directory, leading to potential security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.