Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-2306

An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known.

The attack requires the attacker to know the documents UUIDv4.

  • Published: May 16, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-2306
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.9
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N