Syncpilot Live Contract Improper Access Control Vulnerability Allowing Unauthorized File Downloads

Vulnerability

A vulnerability allowing improper access control in the file download feature of Syncpilot Live Contract has been identified. This issue enables users to download sensitive documents without authentication, provided they know the document's UUIDv4. The vulnerability affects Live Contract versions through 5.4.11, 5.5.3, and 5.6.2.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive documents.

Remediation

Users can upgrade to Syncpilot Live Contract versions 5.4.12, 5.5.4, or 5.6.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.