CVE-2025-1982

HIGH

Ready's Attachment Upload - Path Traversal

Title source: llm
STIX 2.1

Description

Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.

Scores

CVSS v4 7.1
EPSS 0.0025
EPSS Percentile 48.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-552
Status published
Products (2)
Symfonia/Ready_ 7.0.0.0 - 7.19.39.23
Symfonia/Ready_ 8.0.0.0 - 8.0.2.3
Published Apr 16, 2025
Tracked Since Feb 18, 2026