Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20251218-release-2025-10-1/ |
|
History
Fri, 19 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. | |
| Title | Insecure direct object reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2025-12-19T12:58:15.508Z
Reserved: 2025-12-18T11:48:11.819Z
Link: CVE-2025-14881
Updated: 2025-12-19T12:58:08.955Z
Status : Received
Published: 2025-12-19T13:16:01.467
Modified: 2025-12-19T13:16:01.467
Link: CVE-2025-14881
No data.
OpenCVE Enrichment
No data.