CRITICAL🇵🇱 Wersja polska

CVE-2025-22927

CVSS 9.1v3.1pub. 2025-04-03upd. 2025-07-17

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.

🤖 AI Analysis
How it works

The attacker sends a crafted HTTP POST request to the /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename endpoint, manipulating the filename parameter to contain path traversal sequences (e.g., ../). The server does not properly validate the path passed in the parameter, allowing it to escape the allowed directory. As a result, it is possible to read or overwrite system files accessible to the web server process.

Impact

An attacker can gain unauthorized access to sensitive files on the server (e.g., configuration files, student data) or overwrite them, violating the confidentiality and integrity of stored data.

Mitigation & patch

Apply patches available from the vendor according to references. The vendor's repository is available at https://github.com/OS4ED/openSIS-Classic. Until an update is applied, it is recommended to restrict network access to the openSIS instance and monitor suspicious requests to the Modules.php endpoint.

Who is affected

OS4ED openSIS versions 8.0 through 9.1 (openSIS-Classic)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Os4ed Opensis

    APP
    Os4Ed
    8.0 – 9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2021-41691CRITICAL9.8PL ✓same product

SQL Injection w OpenSIS via parametry student_id i TRANSFER[SCHOOL]

CVE-2025-22929CRITICAL9.8PL ✓same product

SQL Injection w Os4Ed openSIS — parametr filter_id

CVE-2025-22926CRITICAL9.8PL ✓same product

Path traversal w openSIS umożliwia nieautoryzowany dostęp do plików

CVE-2025-22928CRITICAL9.8PL ✓same product

SQL Injection w OS4ED openSIS — parametr cp_id w module wiadomości

CVE-2025-22930CRITICAL9.8PL ✓same product

SQL injection w OS4Ed openSIS via parametr groupid w Group.php