Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20251218-release-2025-10-1/ |
|
History
Fri, 19 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. | |
| Title | Insecure direct object reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published: 2025-12-19T12:24:10.523Z
Updated: 2025-12-19T12:58:15.508Z
Reserved: 2025-12-18T11:48:11.819Z
Link: CVE-2025-14881
Updated: 2025-12-19T12:58:08.955Z
Status : Awaiting Analysis
Published: 2025-12-19T13:16:01.467
Modified: 2025-12-19T18:00:18.330
Link: CVE-2025-14881
No data.