Escriptorium

Escriptorium

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 06.08.2026 15:11:28
  • Zuletzt bearbeitet 18.08.2026 18:05:06

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 15:11:23
  • Zuletzt bearbeitet 18.08.2026 18:06:35

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via...

  • EPSS 0.22%
  • Veröffentlicht 06.08.2026 15:11:13
  • Zuletzt bearbeitet 18.08.2026 18:06:45

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata ...

  • EPSS 0.23%
  • Veröffentlicht 06.08.2026 15:11:08
  • Zuletzt bearbeitet 18.08.2026 18:05:16

Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, v...

  • EPSS 0.27%
  • Veröffentlicht 06.08.2026 15:11:03
  • Zuletzt bearbeitet 18.08.2026 18:05:23

Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training...