An Improper Access Control vulnerability was
identified in the file download functionality. This vulnerability allows users
to download sensitive documents without authentication, if the URL is known.
The attack
requires the attacker to know the documents UUIDv4.
CVE ID: CVE-2025-2306
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.9
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor: SYNCPILOT
Product: LIVE CONTRACT
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 15.74% (scored less or equal to compared to others)
EPSS Date: 2025-06-14 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false