HIGH
Uniong|WebITR - Arbitrary File Reading through Path Traversal
Published Aug 22, 2025
7.1
HIGHCVSS 4.0
EPSS 0.55%
Description
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Affected products
-
- Version 0StatusaffectedConstraints<=2_1_0_32
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Weaknesses (1)
References (2)
- https://www.twcert.org.tw/en/cp-139-10329-a1c5d-2.html third-party-advisoryThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-10328-dbc35-1.html third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10329-a1c5d-2.html | third-party-advisoryThird Party Advisory | |
| https://www.twcert.org.tw/tw/cp-132-10328-dbc35-1.html | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Aug 22, 2025
Updated Aug 22, 2025
Reserved Aug 20, 2025
Link CVE-2025-9259
CISA Vulnrichment
Updated Aug 22, 2025