go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Uniong|WebITR - 6 Vulnerabilities

TVN ID TVN-202508003
CVE ID CVE-2025-9254, CVE-2025-9255, CVE-2025-9256, CVE-2025-9257, CVE-2025-9258, CVE-2025-9259
CVSS CVE-2025-9254:
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2025-9255:
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2025-9256:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2025-9257:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2025-9258:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2025-9259:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products WebITR 2_1_0_32 and earlier
Description Missing Authentication(CVE-2025-9254):
Unauthenticated remote attackers can log into the system as arbitrary users by exploiting a specific functionality.

SQL Injection(CVE-2025-9255):
Unauthenticated remote attackers can inject arbitrary SQL commands to read database contents.

Arbitrary File Reading(CVE-2025-9256, CVE-2025-9257, CVE-2025-9258, CVE-2025-9259):
Remote attackers with regular privileges can exploit Absolute Path Traversal to download arbitrary system files.
Solution Update to version 2_1_0_33 or later
Credit Linwz(DEVCORE)
Public Date 2025-08-20
Top