CVE-2025-22923: OS4ED Opensis

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.

Affected products

  • OS4ED Opensis: from 8.0, up to and including 9.1

Published 2025-04-02. Last modified 2026-06-17.