CVE-2018-25408
The Open ISES Project 3.30A Path Traversal Arbitrary File Download
CVSS Score
7.5
EPSS Score
0.2%
EPSS Percentile
46th
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.
| CWE | CWE-22 |
| Vendor | openises |
| Product | open ises project |
| Published | May 30, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for openises open ises project
Be the first to know when new high vulnerabilities affecting openises open ises project are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Openises / Open ISES Project
3.30A
References
exploit-db.com: https://www.exploit-db.com/exploits/45655 openises.sourceforge.net: http://openises.sourceforge.net/ sourceforge.net: https://sourceforge.net/projects/openises/files/latest/download vulncheck.com: https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-path-traversal-arbitrary-file-download
Credits
Ihsan Sencan