CVE-2026-25809
PlaciPy Code Execution Allowed Without Assessment Active State Validation
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Praskla-Technology · assessment-placipy¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →