CVE-2026-23878
EUVD-2026-330419.01.2026, 19:16
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download any documents (PDFs, attachments) associated with any submission. The problem was patched in commit ceacd5f1476458792c44c6a993670f02c984b4a0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hotcrp | hotcrp | 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration