CVE-2025-8909

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wellchoose:organization_portal_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-13 09:15

Updated : 2025-08-21 00:34


NVD link : CVE-2025-8909

Mitre link : CVE-2025-8909

CVE.ORG link : CVE-2025-8909


JSON object : View

Products Affected

wellchoose

  • organization_portal_system
CWE
CWE-36

Absolute Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')