Scripta eScriptorium是Scripta团队的一个手写文本识别与标注平台。 Scripta eScriptorium 26.04.1及之前版本存在授权问题漏洞,该漏洞源于OcrModelRight创建和删除视图缺少授权,所有权检查位于get_context_data()中,仅在GET渲染路径执行,导致远程认证用户可通过POST请求授予自己访问其他用户私有OCR模型以及撤销任何用户的OCR模型访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Scripta | eScriptorium | ≤ 26.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Scripta | eScriptorium | 0 ~ 26.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18258 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-18359 | 8.5 HIGH | Server-Side Request Forgery (SSRF) in eScriptorium |
| CVE-2026-18275 | 6.5 MEDIUM | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-18276 | 4.3 MEDIUM | Missing Authorization in eScriptorium |
No comments yet