CVE-2026-25811

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-09 22:16

Updated : 2026-02-18 20:30


NVD link : CVE-2026-25811

Mitre link : CVE-2026-25811

CVE.ORG link : CVE-2026-25811


JSON object : View

Products Affected

prasklatechnology

  • placipy
CWE
CWE-863

Incorrect Authorization