Improper Access Control vulnerability in LIVE CONTRACT
Vulnerability Description
An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known. The attack requires the attacker to know the documents UUIDv4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2306
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Felix Schmid <felix.schmid@cirosec.de>
References
More from SYNCPILOT
View All →Affected Vendor
SYNCPILOT
View all reports →