go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

WellChoose|Organization Portal System - 6 Vulnerabilities

TVN ID TVN-202508002
CVE ID CVE-2025-8909, CVE-2025-8910, CVE-2025-8911, CVE-2025-8912, CVE-2025-8913, CVE-2025-8914
CVSS CVE-2025-8909:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2025-8910, CVE-2025-8911:
6.1 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2025-8912:
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2025-8913:
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2025-8914:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products Organization Portal System version IFTOP_P3_2_1_196 and earlier
Description Arbitrary File Reading(CVE-2025-8909):
Remote attackers with regular privileges can exploit Absolute Path Traversal to download arbitrary system files.

Reflected Cross-Site Scripting(CVE-2025-8910, CVE-2025-8911):
Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.

Arbitrary File Reading(CVE-2025-8912):
Unauthenticated remote attackers can exploit Absolute Path Traversal to download arbitrary system files.

Local File Inclusion(CVE-2025-8913):
Unauthenticated remote attackers can execute arbitrary code on the server.

SQL Injection(CVE-2025-8914):
Unauthenticated remote attackers can inject arbitrary SQL commands to read database contents.
Solution Update to version IFTOP_P3_2_1_197 or later
Credit Lai Yu-Jen(CHT Security):
CVE-2025-8909
CVE-2025-8910

BTtea(CHT Security):
CVE-2025-8911
CVE-2025-8912
CVE-2025-8913
CVE-2025-8914
Public Date 2025-08-13
Top