CVE-2025-22931: High severity os4ed opensis-classic vulnerability
Published Apr 3, 2025
·Updated
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
Affected Software
2 affected components
OS4ED openSIS>=7.0<=9.1
OS4ED openSIS>=7.0<=9.1
Event History
Apr 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22931?
CVE-2025-22931 has a critical severity level as it allows unauthenticated attackers to access sensitive files.
2
How do I fix CVE-2025-22931?
To fix CVE-2025-22931, implement proper access controls and validate user permissions before allowing access to the /assets/stafffiles component.
3
Which versions of OS4ED openSIS are affected by CVE-2025-22931?
CVE-2025-22931 affects OS4ED openSIS versions from 7.0 to 9.1 inclusive.
4
What type of vulnerability is CVE-2025-22931?
CVE-2025-22931 is categorized as an insecure direct object reference (IDOR).
5
Can CVE-2025-22931 be exploited easily?
Yes, CVE-2025-22931 can be easily exploited by unauthenticated attackers to access staff files.