CVE 3.8 LOW

Insecure direct object reference_CVE-2025-14882

3.8 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U

Description

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

Basic Information

ID CVE-2025-14882
Source rami.io
Published Dec 19, 2025 at 12:24

Affected Product

Vendor pretix
Product pretix-offlinesales
Version 1.12.0
Affected Versions pretix pretix-offlinesales 1.12.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.