← Back

CVE-2025-2306

nvd nist
Published: May 16, 2025Modified: May 16, 2025

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: a341c0d1-ebf7-493f-a84e-38cf86618674 (Secondary)

Description

An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known. The attack requires the attacker to know the documents UUIDv4.

References (1)

Source: a341c0d1-ebf7-493f-a84e-38cf86618674

Timeline

No history available yet.