CNNVD-202508-2811 Information

CNNVD ID

CNNVD-202508-2811

CVE-2025-9258

  • CNNVD Published: 2025-08-22

Description (Chinese)

Uniong WebITR是中国凯发(Uniong)公司的一款在线考勤系统。 Uniong WebITR存在安全漏洞,该漏洞源于容易受到绝对路径遍历攻击,可能导致远程攻击者下载任意系统文件。

Description (English)

Uniong WebITR is an online attendance system of Uniong China. There is a security loophole in Uniong WebITr, which stems from its vulnerability to absolute routing, which may result in remote attackers downloading any system file.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

凯发

Published

2025-08-22

Last Modified

2026-02-24

References

https://www.twcert.org.tw/tw/cp-132-10328-dbc35-1.html https://www.twcert.org.tw/en/cp-139-10329-a1c5d-2.html https://nvd.nist.gov/vuln/detail/CVE-2025-9258

Share on: