PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.
References
| Link | Resource |
|---|---|
| https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-02-09 22:16
Updated : 2026-02-18 20:30
NVD link : CVE-2026-25811
Mitre link : CVE-2026-25811
CVE.ORG link : CVE-2026-25811
JSON object : View
Products Affected
prasklatechnology
- placipy
CWE
CWE-863
Incorrect Authorization
