CVE-2025-2306

MEDIUM

SYNCPILOT LIVE CONTRACT 3-5.4.11, 5.5-5.5.3, 5.6-5.6.2 - Unauthenticated Sensitive Document Download via UUIDv4

Title source: llm
STIX 2.1

Description

An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known. The attack requires the attacker to know the documents UUIDv4.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0040
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (3)
SYNCPILOT/LIVE CONTRACT 3 - 5.4.12
SYNCPILOT/LIVE CONTRACT 5.5 - 5.5.4
SYNCPILOT/LIVE CONTRACT 5.6 - 5.6.3
Published May 16, 2025
Tracked Since Feb 18, 2026