In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.
History

Fri, 09 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 19:45:00 +0000

Type Values Removed Values Added
Description In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-09T21:26:03.111Z

Reserved: 2025-12-12T00:00:00.000Z

Link: CVE-2025-67810

cve-icon Vulnrichment

Updated: 2026-01-09T21:25:58.454Z

cve-icon NVD

Status : Received

Published: 2026-01-09T20:15:51.887

Modified: 2026-01-09T22:16:00.700

Link: CVE-2025-67810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.