CVE-2025-2306

Published May 16, 2025

Last updated a month ago

Overview

Description
An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known. The attack requires the attacker to know the documents UUIDv4.
Source
a341c0d1-ebf7-493f-a84e-38cf86618674
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.9
Impact score
3.6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

a341c0d1-ebf7-493f-a84e-38cf86618674
CWE-284

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.