CVE-2025-67810
EUVD-2026-168309.01.2026, 20:15
In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| area9lyceum | rhapsode | 1.47.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration