Keiyo System TimeWorks Path Traversal Vulnerability Allowing Arbitrary JSON File Access

Vulnerability

A path traversal vulnerability has been identified in TimeWorks versions 10.0 through 10.3, provided by Keiyo System Co., LTD. This vulnerability allows remote unauthenticated attackers to access arbitrary JSON files on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive JSON files on the server.

Remediation

Users are advised to apply the patch for the web server module as per the instructions provided by the developer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.