| TVN ID | TVN-202508002 |
|---|---|
| CVE ID | CVE-2025-8909, CVE-2025-8910, CVE-2025-8911, CVE-2025-8912, CVE-2025-8913, CVE-2025-8914 |
| CVSS | CVE-2025-8909: 6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2025-8910, CVE-2025-8911: 6.1 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2025-8912: 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2025-8913: 9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2025-8914: 6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| Affected Products | Organization Portal System version IFTOP_P3_2_1_196 and earlier |
| Description | Arbitrary File Reading(CVE-2025-8909): Remote attackers with regular privileges can exploit Absolute Path Traversal to download arbitrary system files. Reflected Cross-Site Scripting(CVE-2025-8910, CVE-2025-8911): Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks. Arbitrary File Reading(CVE-2025-8912): Unauthenticated remote attackers can exploit Absolute Path Traversal to download arbitrary system files. Local File Inclusion(CVE-2025-8913): Unauthenticated remote attackers can execute arbitrary code on the server. SQL Injection(CVE-2025-8914): Unauthenticated remote attackers can inject arbitrary SQL commands to read database contents. |
| Solution | Update to version IFTOP_P3_2_1_197 or later |
| Credit | Lai Yu-Jen(CHT Security): CVE-2025-8909 CVE-2025-8910 BTtea(CHT Security): CVE-2025-8911 CVE-2025-8912 CVE-2025-8913 CVE-2025-8914 |
| Public Date | 2025-08-13 |
