{"id":"CVE-2019-15302","details":"The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.","modified":"2026-04-10T04:15:00.349865Z","published":"2019-09-11T21:15:11.877Z","references":[{"type":"ADVISORY","url":"https://github.com/xwiki-labs/cryptpad/releases/tag/3.0.0"},{"type":"FIX","url":"https://github.com/xwiki-labs/cryptpad/commits/staging"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cryptpad/cryptpad","events":[{"introduced":"0"},{"fixed":"166ab65cd47a64e020528089244ed5be34f6e3c8"}]},{"type":"GIT","repo":"https://github.com/xwiki-labs/cryptpad","events":[{"introduced":"0"},{"fixed":"166ab65cd47a64e020528089244ed5be34f6e3c8"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.0.0"}]}}],"versions":["0.2.0","0.3.0","1.1.0","1.1.1","1.11.0","1.12.0","1.18.0","1.2.0","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.3.0","1.4.0","1.8.0","1.9.0","2.17.0","2.17.05","2.17.06","2.19.0","2.21.0","2.22.0","2.25.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15302.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}