3.8
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U
Description
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Basic Information
ID
CVE-2025-14882
Source
rami.io
Published
Dec 19, 2025 at 12:24
Affected Product
Vendor
pretix
Product
pretix-offlinesales
Version
1.12.0
Affected Versions
pretix pretix-offlinesales 1.12.0