« Volver al listado

Prasklatechnology

Prasklatechnology Placipy: vulnerabilidades y CVE

Prasklatechnology Placipy tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses10
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25875Crítica (9.3)0.51%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-controlled JWT claims (role and scope) without enforcing server-side…
CVE-2026-25814Crítica (9.3)0.60%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter construction without validation or…
CVE-2026-25813Alta (8.7)0.44%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without masking or redaction.
CVE-2026-25812Crítica (9.3)0.21%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.
CVE-2026-25811Media (5.3)0.38%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating…
CVE-2026-25876Media (5.3)0.46%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership…
CVE-2026-25810Media (5.3)0.46%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization…
CVE-2026-25809Media (5.3)0.55%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no…
CVE-2026-25806Media (5.3)0.39%—9 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:email/status, and DELETE /api/students/:email routes in…
CVE-2026-25753Crítica (9.3)0.51%—6 feb 2026
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1
  4. T1078.001 Default Accounts1
  5. T1185 Browser Session Hijacking1
  6. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.