Uniong WebITR Absolute Path Traversal Vulnerability Allowing Arbitrary File Reading

Vulnerability

A vulnerability allowing arbitrary file reading has been identified in Uniong's WebITR, specifically in version 2_1_0_32 and earlier. This vulnerability arises from an absolute path traversal issue, which remote attackers with regular privileges can exploit to download arbitrary system files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system files, potentially allowing for further exploitation or information disclosure.

Remediation

Users are advised to update WebITR to version 2_1_0_33 or later.

Added: Aug 22, 2025, 12:18 PM
Updated: Aug 22, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.