CVE-2025-22926: Path Traversal
Published Apr 3, 2025
·Updated
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
Affected Software
2 affected components
OS4ED openSIS>=8.0<=9.1
OS4ED openSIS>=8.0<=9.1
Event History
Apr 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22926?
CVE-2025-22926 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2025-22926?
To fix CVE-2025-22926, upgrade OS4ED openSIS to version 9.2 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2025-22926?
CVE-2025-22926 is a directory traversal vulnerability that allows attackers to access unintended files on the server.
4
Which versions of openSIS are affected by CVE-2025-22926?
CVE-2025-22926 affects OS4ED openSIS versions 8.0 to 9.1.
5
What actions can attackers perform with CVE-2025-22926?
Attackers can execute arbitrary code on the server by sending crafted POST requests to exploit CVE-2025-22926.