CVE-2025-1982: Symfonia Ready
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.
Affected products
- Symfonia Ready: from 7.0.0.0, up to and including 7.19.39.23; from 8.0.0.0, up to and including 8.0.2.3
Published 2025-04-16. Last modified 2026-06-17.