Home
HIGH: 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 20.19
affected
Description
Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).
Problem types
Product status
Any version before 20.19
Credits
Jakub Płatek (NASK-PIB)
References
cert.pl/en/posts/2025/05/CVE-2025-4430/
www.gov.pl/web/ezd-rp