CyberRota Analysis
AI-GeneratedThe vulnerability allows remote authenticated users to bypass authorization controls in the Scripta/eScriptorium API, enabling them to read, modify, and delete other users' transcription content by manipulating primary keys in the request body. This could lead to significant data breaches and unauthorized access to sensitive information. Organizations using affected versions should prioritize patching this issue to protect user data and maintain compliance.
Original NVD Description
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset