We found results for “”
CVE-2025-14882
Good to know:
Date: December 19, 2025
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Authorization Bypass Through User-Controlled Key
CWE-639Top Fix
Upgrade Version
Upgrade to version pretix - 2025.10.1;pretix - 2025.9.3;pretix - 2025.8.3;https://github.com/pretix/pretix.git - v2025.8.3;https://github.com/pretix/pretix.git - v2025.9.3;https://github.com/pretix/pretix.git - v2025.10.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


