CVE-2025-15066

MEDIUM

Innorix WP - Path Traversal via Exam Directory

Title source: llm
STIX 2.1

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

References (2)

Core 2
Core References
Various Sources
https://www.innorix.com/

Scores

CVSS v3 6.2
EPSS 0.0014
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-862
Status published
Products (1)
Innorix/Innorix WP
Published Dec 29, 2025
Tracked Since Feb 18, 2026