CVE-2025-22923 | OS4ED openSIS up to 9.1 HTTP POST Request Staff.php&removefile path traversal
A vulnerability was found in OS4ED openSIS up to 9.1. It has been classified as critical. This affects an unknown part of the file /Modules.php?modname=users/Staff.php&removefile of the component HTTP POST Request Handler. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-22923. Access to the local network is required for this attack. There is no exploit available.