Directory Traversal Vulnerability in OS4ED openSIS by OS4ED
CVE-2025-22923
8.8HIGH
What is CVE-2025-22923?
A security flaw in OS4ED openSIS versions 8.0 to 9.1 allows remote attackers to exploit a directory traversal vulnerability. By sending a specially crafted POST request to the '/Modules.php?modname=users/Staff.php&removefile' endpoint, attackers can manipulate the server to delete arbitrary files. This vulnerability poses a risk to the integrity of the file system, potentially compromising sensitive data. It highlights the necessity for robust input validation and secure coding practices to defend against such threats.
