P
laciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
References
| Link | Resource |
|---|---|
| https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-cc32-rp29-w9x7 | Mitigation Vendor Advisory |
Configurations
History
11 Feb 2026, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-cc32-rp29-w9x7 - Mitigation, Vendor Advisory | |
| First Time |
Prasklatechnology
Prasklatechnology placipy |
|
| CPE | cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:* |
09 Feb 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 21:15
Updated : 2026-02-11 19:41
NVD link : CVE-2026-25809
Mitre link : CVE-2026-25809
CVE.ORG link : CVE-2026-25809
JSON object : View
Products Affected
CWE
CWE-285
Improper Authorization