CVE-2025-8909

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wellchoose:organization_portal_system:*:*:*:*:*:*:*:*

History

21 Aug 2025, 00:34

Type Values Removed Values Added
First Time Wellchoose
Wellchoose organization Portal System
References () https://www.twcert.org.tw/en/cp-139-10325-70192-2.html - () https://www.twcert.org.tw/en/cp-139-10325-70192-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10321-3cae5-1.html - () https://www.twcert.org.tw/tw/cp-132-10321-3cae5-1.html - Third Party Advisory
CPE cpe:2.3:a:wellchoose:organization_portal_system:*:*:*:*:*:*:*:*
CWE CWE-22

13 Aug 2025, 17:33

Type Values Removed Values Added
Summary
  • (es) Organization Portal System desarrollado por WellChoose tiene una vulnerabilidad de lectura arbitraria de archivos, que permite a atacantes remotos con privilegios regulares explotar Absolute Path Traversal para descargar archivos de sistema arbitrarios.

13 Aug 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 09:15

Updated : 2025-08-21 00:34


NVD link : CVE-2025-8909

Mitre link : CVE-2025-8909

CVE.ORG link : CVE-2025-8909


JSON object : View

Products Affected

wellchoose

  • organization_portal_system
CWE
CWE-36

Absolute Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')