CVE-2018-25408: Openises Open Ises Project
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.
Affected products
- Openises Open Ises Project: version 3.30A only
Published 2026-05-30. Last modified 2026-07-22.