Path Traversal Vulnerability in Opencast Educational Content Platform
CVE-2025-55202

2.7LOW

Key Information:

Vendor

Opencast

Status
Vendor
CVE Published:
29 August 2025

What is CVE-2025-55202?

Opencast, an open-source educational audio and video content management platform, has a significant path traversal vulnerability affecting versions 18.0 and earlier than 17.7 in its UI config module. The vulnerability arises from inadequate protections, allowing attackers to exploit file path checks that do not adequately verify file separators. This flaw could potentially grant unauthorized access to files in directories that share similar starting paths. Users are strongly advised to upgrade to versions 17.7 or 18.1 or to implement mitigations that involve inspecting folder names that closely resemble the ui-config folder path to enhance security.

Affected Version(s)

opencast < 17.7 < 17.7

opencast = 18.0 = 18.0

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55202 : Path Traversal Vulnerability in Opencast Educational Content Platform