CVE-2018-25408: Openises Open Ises Project

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.

Affected products

  • Openises Open Ises Project: version 3.30A only

Published 2026-05-30. Last modified 2026-07-22.