PT-2025-48066 · Primakon · Primakon Pi Portal
Published
2025-11-25
·
Updated
2025-12-01
·
CVE-2025-64066
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Primakon Pi Portal version 1.0.18
Description
The
/api/v2/user/register endpoint in Primakon Pi Portal is susceptible to a Broken Access Control issue. The endpoint does not enforce authorization checks, enabling unauthenticated attackers to submit POST requests to create new user accounts directly in the application’s local database. This circumvents the expected security design, which depends on an external Identity Provider for initial user registration and assumes internal user creation is restricted to administrators. This issue can potentially be combined with other weaknesses to escalate privileges and fully compromise the application. The endpoint can also be used to enumerate existing user accounts, which could facilitate social engineering or more focused attacks.Recommendations
Implement proper authorization checks on the
/api/v2/user/register endpoint to ensure only authenticated and authorized users can create new accounts.Exploit
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Primakon Pi Portal