HarborGuard / CVE
Back to search
CRITICALCVE-2026-25812Published Modified CNA GitHub_M

CVE-2026-25812: PlaciPy is Missing CSRF Protection on State-Changing Endpoints

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Praskla-Technology / assessment-placipy
    = 1.0.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-25812: PlaciPy is Missing CSRF Protection on State-Changing Endpoints | HarborGuard CVE