Executive brief
GG Soft PaperWork, a document management and workflow automation platform, contains a security flaw that allows users to bypass authorization controls. By manipulating specific identifiers, an authenticated user could gain access to data or perform actions they are not permitted to see or do. This could lead to the unauthorized exposure of sensitive corporate documents or internal business records.
Technical details
An authorization bypass vulnerability (CWE-639) exists in GG Soft PaperWork versions 5.2.0.9427 through 6.0. The flaw stems from the application's reliance on user-controlled keys or identifiers to perform authorization checks. An authenticated attacker with low privileges can manipulate these identifiers in network requests to access or modify resources belonging to other users or the system. The attack is reachable over the network and does not require user interaction, though it does require valid credentials. A fix is available in version 6.0.
Affected products
- GG Soft Software Services Inc. PaperWork 5.2.0.9427 to 6.0 (exclusive)
Timeline
- 2025-12-17: disclosed
- 2025-12-17: advisory