CVE-2025-64062
- EPSS 0.06%
- Veröffentlicht 25.11.2025 18:15:53
- Zuletzt bearbeitet 01.12.2025 13:25:19
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.c...
CVE-2025-64061
- EPSS 0.04%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:43:55
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can mak...
CVE-2025-64066
- EPSS 0.15%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:19:46
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new us...
CVE-2025-64063
- EPSS 0.06%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:22:04
Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restri...
CVE-2025-64064
- EPSS 0.05%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:22:20
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change thei...
CVE-2025-64065
- EPSS 0.06%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:22:29
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticate...
CVE-2025-64067
- EPSS 0.04%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 14:22:52
Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access...