« Volver al listado

Primakon

Primakon Project Contract Management: vulnerabilidades y CVE

Primakon Project Contract Management tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-64067Media (5.3)0.23%—25 nov 2025
Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the…
CVE-2025-64065Alta (8.8)0.29%—25 nov 2025
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure.…
CVE-2025-64064Alta (8.8)0.29%—25 nov 2025
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user…
CVE-2025-64063Crítica (9.8)0.38%—25 nov 2025
Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative…
CVE-2025-64066Alta (8.6)0.28%—25 nov 2025
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform…
CVE-2025-64062Alta (8.8)0.29%—25 nov 2025
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an…
CVE-2025-64061Media (4.3)0.22%—25 nov 2025
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1078.001 Default Accounts2
  3. T1190 Exploit Public-Facing Application2
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1
  6. T1136 Create Account1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.