PT-2026-68612 · Scripta · Escriptorium
CVE-2026-18277
·
Published
2026-08-06
·
Updated
2026-08-18
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Scripta eScriptorium versions prior to 26.04.2
Description
Missing authorization in the OcrModelRight create and delete views allows a remote authenticated user to grant themselves access to another user's private OCR model or revoke any user's OCR model access via a POST request. This occurs because the ownership check is implemented within the
get context data() function, which only executes during the GET rendering path, leaving the POST request path unprotected.Recommendations
Update Scripta eScriptorium to version 26.04.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Escriptorium