7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Basic Information
ID
CVE-2025-9259
Source
twcert
Published
Aug 22, 2025 at 11:46
Affected Product
Vendor
Uniong
Product
WebITR
Affected Versions
Uniong WebITR 0