Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://cert.pl/posts/2025/04/CVE-2025-1980 | third party advisory |
https://cert.pl/en/posts/2025/04/CVE-2025-1980 | third party advisory |
https://ready-os.com/pl/ | product |