CVE-2025-14881

LOW

Pypi Pretix < 2025.10.1 - IDOR

Title source: rule
STIX 2.1

Description

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

References (1)

Core 1
Core References

Scores

CVSS v4 3.8
EPSS 0.0007
EPSS Percentile 22.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (5)
pretix/pretix 1.0.0 - 2025.8.0
pretix/pretix 2025.10.0 - 2025.11.0
pretix/pretix 2025.8.0 - 2025.9.0
pretix/pretix 2025.9.0 - 2025.10.0
pypi/pretix 2025.10.0 - 2025.10.1PyPI
Published Dec 19, 2025
Tracked Since Feb 18, 2026