CVE-2025-9258: Uniong Webitr
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Affected products
- Uniong Webitr: before 2_1_0_33 (fixed in 2_1_0_33)
Published 2025-08-22. Last modified 2026-06-17.