Syncpilot Live Contract Improper Access Control Vulnerability Allowing Unauthorized File Downloads
Vulnerability
A vulnerability allowing improper access control in the file download feature of Syncpilot Live Contract has been identified. This issue enables users to download sensitive documents without authentication, provided they know the document's UUIDv4. The vulnerability affects Live Contract versions through 5.4.11, 5.5.3, and 5.6.2.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive documents.
Remediation
Users can upgrade to Syncpilot Live Contract versions 5.4.12, 5.5.4, or 5.6.3 to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
6.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
