HarborGuard / CVE
Back to search
CRITICALCVE-2026-25753Published Modified CNA GitHub_M

CVE-2026-25753: PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Praskla-Technology / assessment-placipy
    <= 1.0.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-25753: PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover) | HarborGuard CVE