CVE-2025-14882
Insecure direct object reference
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U
Productos afectados
pretix · pretix-offlinesales¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →