Arbitrary File Reading vulnerability in WebITR by Uniong
CVE-2025-9258
7.1HIGH
What is CVE-2025-9258?
An Arbitrary File Reading vulnerability exists in WebITR developed by Uniong, enabling remote attackers with normal user privileges to exploit Absolute Path Traversal vulnerabilities. This flaw allows unauthorized access to download sensitive system files, potentially exposing critical information to malicious users. Prompt patching is advised to mitigate risks associated with this vulnerability.
Affected Version(s)
WebITR 0 <= 2_1_0_32