Description
A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
7.0.0.0
8.0.0.0
Credits
Maksymilian Kubiak, Sławomir Zakrzewski, Jakub Stankiewicz - Afine Team
References
cert.pl/posts/2025/04/CVE-2025-1980
cert.pl/en/posts/2025/04/CVE-2025-1980
ready-os.com/pl/