CVE-2025-8912

7.5

WellChoose · Organization Portal System

WellChoose Organization Portal System is vulnerable to absolute path traversal, allowing unauthenticated remote attackers to read arbitrary system files.

Executive summary

An unauthenticated absolute path traversal vulnerability in the WellChoose Organization Portal System allows remote attackers to access sensitive system files, posing a high risk to data confidentiality.

Vulnerability

The application fails to properly sanitize user input, allowing unauthenticated remote attackers to perform absolute path traversal attacks to read sensitive files on the underlying host.

Business impact

Successful exploitation allows unauthorized access to sensitive configuration files, credentials, or system data, which can lead to full system compromise or facilitate further attacks within the environment. With a CVSS score of 7.5, this high-severity vulnerability represents a significant risk to organizational data integrity and confidentiality that requires immediate attention.

Remediation

Immediate Action: Update the WellChoose Organization Portal System to version IFTOP_P3_2_1_197 or later as specified by the vendor.

Proactive Monitoring: Review web server access logs for anomalous requests containing directory traversal sequences, such as absolute paths, that deviate from expected application behavior.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block path traversal attempts, specifically targeting requests that attempt to access restricted system files.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with its unauthenticated nature, necessitates an immediate patching cycle. Organizations should prioritize updating to version IFTOP_P3_2_1_197 to eliminate the exposure window and prevent potential unauthorized file access.

More WellChoose CVEs

Sources