Executive brief
Saysis Web Portal, a platform used for corporate web services, contains a security flaw that allows unauthorized access to internal files. An attacker can exploit this to view sensitive system documents or configuration files that should be restricted. This could lead to the exposure of confidential business data or credentials, potentially compromising the entire server.
Technical details
A path traversal vulnerability (CWE-22) exists in Saysis Web Portal versions 3.1.9 and 3.2.0. The flaw stems from improper limitation of pathnames, allowing an attacker to use special characters (such as '../') to navigate the server's file system. This is a network-based attack that requires no authentication or user interaction. Successful exploitation allows an attacker to read sensitive files on the host operating system. The issue is addressed in version 3.2.1.
Affected products
- Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal 3.1.9, 3.2.0 before 3.2.1
Timeline
- 2025-09-25: disclosed
- 2025-09-25: advisory