We found results for “”
CVE-2025-14881
Good to know:
Date: December 19, 2025
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Authorization Bypass Through User-Controlled Key
CWE-639Top Fix
Upgrade Version
Upgrade to version pretix - 2025.10.1;pretix - 2025.9.3;pretix - 2025.8.3;https://github.com/pretix/pretix.git - v2025.8.3;https://github.com/pretix/pretix.git - v2025.9.3;https://github.com/pretix/pretix.git - v2025.10.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


