CyberRota Analysis
AI-GeneratedThe vulnerability arises from a lack of authorization in the websocket consumer of Scripta eScriptorium, allowing remote authenticated users to access and monitor the event streams of other users' documents. This exposure can lead to unauthorized observation of sensitive activities, including segmentation and transcription processes. Organizations using this software should prioritize addressing this issue to protect user privacy and prevent potential data leaks.
Original NVD Description
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check