CVE-2025-22927: OS4ED Opensis
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
Affected products
- OS4ED Opensis: from 8.0, up to and including 9.1
Published 2025-04-03. Last modified 2026-06-17.