CVE-2025-2306

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
16/05/2025
Last modified:
16/05/2025

Description

An Improper Access Control vulnerability was<br /> identified in the file download functionality. This vulnerability allows users<br /> to download sensitive documents without authentication, if the URL is known.<br /> <br /> <br /> <br /> The attack<br /> requires the attacker to know the documents UUIDv4.

References to Advisories, Solutions, and Tools