CVE-2025-22923: Path Traversal
Published Apr 2, 2025
·Updated
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Affected Software
2 affected components
OS4ED openSIS>=8.0<9.1
OS4ED openSIS>=8.0<=9.1
Event History
Apr 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22923?
CVE-2025-22923 is considered a critical vulnerability due to its potential to allow unauthorized file deletion through directory traversal.
2
How do I fix CVE-2025-22923?
To fix CVE-2025-22923, upgrade your OS4ED openSIS installation to version 9.2 or later to mitigate the vulnerability.
3
What software is affected by CVE-2025-22923?
CVE-2025-22923 affects OS4ED openSIS versions from 8.0 to 9.1.
4
Is CVE-2025-22923 exploitable remotely?
Yes, CVE-2025-22923 can be exploited remotely by sending a crafted POST request to the vulnerable endpoint.
5
What type of attack is associated with CVE-2025-22923?
CVE-2025-22923 is associated with directory traversal attacks that allow file deletion.