CyberRota Analysis
AI-GeneratedDocumenso versions prior to 2.13.0 are vulnerable due to an unauthenticated endpoint that allows arbitrary PDF file uploads without any authentication or session validation. This can lead to resource exhaustion and database clutter, potentially impacting system performance and availability. Organizations using affected versions should prioritize patching to mitigate the risk of abuse and ensure system integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.