Home
LOW: 3.8 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:UDefault status
unaffected
1.12.0 (python)
affected
Description
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
1.12.0 (python)
References
pretix.eu/about/en/blog/20251218-release-2025-10-1/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.