Description
A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
In Papermerge DMS bis 3.5.3 wurde eine Schwachstelle gefunden. Hierbei betrifft es unbekannten Programmcode der Komponente Authorization Token Handler. Die Veränderung resultiert in improper authorization. Der Angriff lässt sich über das Netzwerk starten. Die Schwachstelle wurde öffentlich offengelegt und könnte ausgenutzt werden.
Problem types
Incorrect Privilege Assignment
Product status
3.5.1
3.5.2
3.5.3
Timeline
| 2025-09-10: | Advisory disclosed |
| 2025-09-10: | VulDB entry created |
| 2025-09-10: | VulDB entry last update |
Credits
unhingedazrael (VulDB User)
References
vuldb.com/?id.323482 (VDB-323482 | Papermerge DMS Authorization Token improper authorization)
vuldb.com/?ctiid.323482 (VDB-323482 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/?submit.639750 (Submit #639750 | Github Papermerge 3.5.3 Improper Access Controls)
docs.google.com/...0Z8_MZdydVdmE_Ak09ra2NHw/edit?usp=sharing