CVE-2025-8909: Wellchoose Organization Portal System
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Affected products
- Wellchoose Organization Portal System: before IFTOP_P3_2_1_197 (fixed in IFTOP_P3_2_1_197)
Published 2025-08-13. Last modified 2026-06-17.