Arbitrary File Reading Vulnerability in Organization Portal System by WellChoose
CVE-2025-8912

8.7HIGH

Key Information:

Vendor

Wellchoose

Vendor
CVE Published:
13 August 2025

What is CVE-2025-8912?

The Organization Portal System developed by WellChoose is susceptible to an Arbitrary File Reading vulnerability. This flaw allows unauthenticated remote attackers to exploit Absolute Path Traversal, enabling them to access and download arbitrary files from the system. Such a vulnerability poses significant risks, as it can lead to unauthorized access to sensitive information within the affected environment. It is crucial for organizations to assess their systems and apply necessary patches to mitigate this risk.

Affected Version(s)

Organization Portal System 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8912 : Arbitrary File Reading Vulnerability in Organization Portal System by WellChoose