Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.
CVE ID: CVE-2025-41428
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.3
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vendor: Keiyo System Co., LTD
Product: TimeWorks
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 19.93% (scored less or equal to compared to others)
EPSS Date: 2025-06-08 (when was this score calculated)