Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://cert.pl/en/posts/2025/05/CVE-2025-4430/ | third party advisory |
https://www.gov.pl/web/ezd-rp | product |