CVE-2025-14101

7.1

GG Soft Software Services Inc · PaperWork

An authorization bypass vulnerability in GG Soft Software Services Inc PaperWork allows attackers with low privileges to exploit trusted identifiers.

Executive summary

A critical authorization bypass vulnerability in PaperWork allows authenticated attackers to manipulate user-controlled keys, leading to unauthorized data access.

Vulnerability

This flaw is an authorization bypass (CWE-639) triggered via user-controlled keys. The CVSS vector (PR:L) indicates that an attacker must possess low-level authenticated access to the application to exploit this vulnerability.

Business impact

The ability to bypass authorization mechanisms poses a significant risk to data confidentiality and integrity. An attacker could potentially access, modify, or manipulate sensitive information that should be restricted to higher-privileged users. Given the CVSS score of 7.1, this represents a high-severity risk that could lead to unauthorized system actions and potential regulatory non-compliance.

Remediation

Immediate Action: Administrators should review vendor guidance from USOM to confirm the availability of a security update and apply it immediately to reach version 6.0 or higher.

Proactive Monitoring: Security teams should monitor application access logs for suspicious patterns, specifically focusing on requests that involve unexpected user identifiers or unauthorized attempts to access administrative resources.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter out malformed requests that attempt to pass unauthorized identifiers to the application backend.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security oversight in the authorization logic of the PaperWork platform. Organizations currently running affected versions are urged to prioritize patching as soon as the vendor release becomes available. In the interim, ensure that internal access controls are strictly enforced and that any accounts with low-level access are monitored for signs of privilege escalation or unauthorized data retrieval.

More GG Soft Software Services Inc CVEs

Sources

Originally found and disclosed by Furkan YILDIZ, Fatih KIRDAR, per the CVE Program record.