Arbitrary File Reading Vulnerability in Organization Portal System by WellChoose
CVE-2025-8909

7.1HIGH

Key Information:

Vendor

Wellchoose

Vendor
CVE Published:
13 August 2025

What is CVE-2025-8909?

The Organization Portal System developed by WellChoose is prone to an Arbitrary File Reading vulnerability. This issue enables remote attackers, holding standard user privileges, to exploit absolute path traversal flaws, thereby gaining unauthorized access to read and download arbitrary system files. The implications of this vulnerability can lead to significant data exposure and potential further exploitation if sensitive files are accessed.

Affected Version(s)

Organization Portal System 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8909 : Arbitrary File Reading Vulnerability in Organization Portal System by WellChoose