CVE-2025-22923: OS4ED Opensis
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Affected products
- OS4ED Opensis: from 8.0, up to and including 9.1
Published 2025-04-02. Last modified 2026-06-17.