CVE-2026-25812

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*

History

18 Feb 2026, 20:10

Type Values Removed Values Added
First Time Prasklatechnology
Prasklatechnology placipy
References () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-99xx-fc63-wc39 - () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-99xx-fc63-wc39 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
Summary
  • (es) PlaciPy es un sistema de gestión de prácticas diseñado para instituciones educativas. En la versión 1.0.0, la aplicación permite solicitudes CORS con credenciales pero no implementa ningún mecanismo de protección CSRF.

09 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 22:16

Updated : 2026-02-18 20:10


NVD link : CVE-2026-25812

Mitre link : CVE-2026-25812

CVE.ORG link : CVE-2026-25812


JSON object : View

Products Affected

prasklatechnology

  • placipy
CWE
CWE-352

Cross-Site Request Forgery (CSRF)