CNNVD-202509-1494 Information

CNNVD ID

CNNVD-202509-1494

CVE-2025-10209

  • CNNVD Published: 2025-09-10

Description (Chinese)

Papermerge DMS是Papermerge DMS开源的一个文档管理系统。 Papermerge DMS 3.5.3及之前版本存在授权问题漏洞,该漏洞源于授权令牌处理不当,可能导致未授权访问。

Description (English)

PaperSmart DMS is a file management system for PaperSmart DMS open source. There was a mandate gap in PaperSmart DMS 3.5.3 and earlier versions, which stemmed from the improper handling of the authorization token, which could lead to unauthorized visits.

Hazard Level

High

Vulnerability Type

授权问题

Affected Vendor

Papermerge DMS

Published

2025-09-10

Last Modified

2026-02-24

References

https://docs.google.com/document/d/19j0mCR-QOuhlxAJMir00Z8_MZdydVdmE_Ak09ra2NHw/edit?usp=sharing https://vuldb.com/?ctiid.323482 https://vuldb.com/?id.323482 https://vuldb.com/?submit.639750 https://docs.google.com/document/d/19j0mCR-QOuhlxAJMir00Z8_MZdydVdmE_Ak09ra2NHw/edit?tab=t.0

Share on: