CVE-2025-22927: Path Traversal
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22927?
CVE-2025-22927 is rated as a high severity vulnerability due to its potential for remote code execution through directory traversal.
How do I fix CVE-2025-22927?
To fix CVE-2025-22927, update OS4ED openSIS to a version later than 9.1, which includes the necessary security patches.
What type of vulnerability is CVE-2025-22927?
CVE-2025-22927 is a directory traversal vulnerability that allows attackers to access unauthorized files on the server.
Which versions of OS4ED openSIS are affected by CVE-2025-22927?
CVE-2025-22927 affects OS4ED openSIS versions from 8.0 through 9.1.
What can attackers achieve using the vulnerability CVE-2025-22927?
Attackers can exploit CVE-2025-22927 to execute arbitrary files on the server, potentially leading to a full system compromise.