CyberRota Analysis
AI-GeneratedThe vulnerability allows a remote authenticated user to bypass authorization controls in Scripta eScriptorium, enabling them to access and modify document parts belonging to other users. This could lead to unauthorized content overwriting, compromising data integrity and confidentiality. Organizations using this software should prioritize addressing this issue to protect user data and maintain trust.
Original NVD Description
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect