P
laciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.
References
| Link | Resource |
|---|---|
| https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh | Mitigation Vendor Advisory |
Configurations
History
18 Feb 2026, 20:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| First Time |
Prasklatechnology
Prasklatechnology placipy |
|
| Summary |
|
|
| References | () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh - Mitigation, Vendor Advisory |
09 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 22:16
Updated : 2026-02-18 20:30
NVD link : CVE-2026-25811
Mitre link : CVE-2026-25811
CVE.ORG link : CVE-2026-25811
JSON object : View
Products Affected
CWE
CWE-863
Incorrect Authorization