CVE-2025-14101: IDOR in GG Soft's PaperWork
Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers.
This issue affects PaperWork: from 5.2.0.9427 before 6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14101?
CVE-2025-14101 has been classified with high severity due to its potential for exploitation through authorization bypass.
How do I fix CVE-2025-14101?
To address CVE-2025-14101, you should upgrade PaperWork to version 6.0 or later, which resolves the vulnerability.
What impact does CVE-2025-14101 have on PaperWork users?
CVE-2025-14101 allows unauthorized access by exploiting trusted identifiers, potentially compromising user data and integrity.
Is CVE-2025-14101 specific to certain versions of PaperWork?
Yes, CVE-2025-14101 affects PaperWork versions from 5.2.0.9427 to just before 6.0.
What should I do if I cannot upgrade from affected versions regarding CVE-2025-14101?
If upgrading is not possible, consider implementing stricter access controls and monitoring to mitigate risks associated with CVE-2025-14101.