CVE-2026-25809
PlaciPy Code Execution Allowed Without Assessment Active State Validation
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
09 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Praskla-Technology · assessment-placipy¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →