CVE ID | CVE-2025-1980 |
Publication date | 16 April 2025 |
Vendor | Symfonia |
Product | Ready_ |
Vulnerable versions | From 7.0.0.0 through 7.19.39.23 |
Vulnerability type (CWE) | Unrestricted Upload of File with Dangerous Type (CWE-434) |
Report source | Report to CERT Polska |
CVE ID | CVE-2025-1981 |
Publication date | 16 April 2025 |
Vendor | Symfonia |
Product | Ready_ |
Vulnerable versions | From 7.0.0.0 through 7.19.39.23 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Report source | Report to CERT Polska |
CVE ID | CVE-2025-1982 |
Publication date | 16 April 2025 |
Vendor | Symfonia |
Product | Ready_ |
Vulnerable versions | From 7.0.0.0 through 7.19.39.23 |
Vulnerability type (CWE) | Files or Directories Accessible to External Parties (CWE-552) |
Report source | Report to CERT Polska |
CVE ID | CVE-2025-1983 |
Publication date | 16 April 2025 |
Vendor | Symfonia |
Product | Ready_ |
Vulnerable versions | From 7.0.0.0 through 7.19.39.23 |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in Symfonia Ready_ software and participated in coordination of their disclosure.
The vulnerability CVE-2025-1980: The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, as it was by default when installed at the turn of 2021 and 2022, it can result in Remote Code Execution.
The vulnerability CVE-2025-1981: Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.
The vulnerability CVE-2025-1982: Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.
The vulnerability CVE-2025-1983: A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.
Credits
We thank Maksymilian Kubiak, Sławomir Zakrzewski and Jakub Stankiewicz from Afine Team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.