Security Advisory
CVE-2025-41428
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Improper limitation of a pathname to a restricted directory (Path Traversal) issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.