Scripta eScriptorium是Scripta团队的一个手写文本识别与标注平台。 Scripta eScriptorium 26.04.1及之前版本存在授权问题漏洞,该漏洞源于授权绕过,即many=True相关字段的queryset限制错误应用于ManyRelatedField而非其子关系,导致限制无效,可能导致远程认证用户对其他用户的文档部分运行分割和转录,覆盖其内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Scripta | eScriptorium | ≤ 26.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Scripta | eScriptorium | 0 ~ 26.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18258 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-18359 | 8.5 HIGH | Server-Side Request Forgery (SSRF) in eScriptorium |
| CVE-2026-18277 | 7.1 HIGH | Missing Authorization in eScriptorium |
| CVE-2026-18276 | 4.3 MEDIUM | Missing Authorization in eScriptorium |
No comments yet