Arbitrary File Reading Vulnerability in WebITR by Uniong
CVE-2025-9257
7.1HIGH
What is CVE-2025-9257?
WebITR, a product developed by Uniong, contains a vulnerability that enables remote attackers with standard user privileges to execute an Absolute Path Traversal technique. This allows them to access and download arbitrary files from the server, presenting a significant risk to sensitive data integrity and system security.
Affected Version(s)
WebITR 0 <= 2_1_0_32