Impact
The vulnerability arises from improper authorization checks in eScriptorium's process and annotation taxonomy serializers; a many=True related field accepts primary keys that bypass the intended queryset restriction, allowing a remotely authenticated user to submit any part ID. This permits the attacker to request segmentation and transcription operations on document parts belonging to other users, resulting in overwritten content. The flaw effectively escalates privileges and compromises the integrity of documents authored by others.
Affected Systems
Scripta's eScriptorium product is affected in releases up to and including 26.04.1, as well as previous versions 1.0.1 and 0.13.9. The fix is included in the newer releases 26.04.2, 1.0.1 and 0.13.9.
Risk and Exploitability
The CVSS 6.5 score classifies this flaw as medium severity; the EPSS score is not available and the vulnerability is not listed in KEV. A remote authenticated user can exploit it by supplying crafted part primary keys to the affected API endpoints, which requires only legitimate login credentials. The attack does not grant arbitrary code execution but can lead to significant data tampering and loss of trust in the platform.
OpenCVE Enrichment