PT-2025-48071 · Unknown · Primakon Pi Portal
Published
2025-11-25
·
Updated
2025-12-01
·
CVE-2025-64063
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Primakon Pi Portal version 1.0.18
Description
The application does not adequately enforce authorization checks for API requests. A standard user can bypass user interface restrictions by directly accessing administrative API endpoints via HTTP requests. This allows unauthorized actions such as modifying or deleting user accounts, changing passwords via the user management API endpoint, accessing sensitive organizational documents through the document retrieval API endpoint, and manipulating core system functions. This can lead to data integrity and confidentiality compromise, and privilege escalation.
Recommendations
Apply stricter authorization checks to all API endpoints to prevent unauthorized access and manipulation of data.
Exploit
Fix
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Primakon Pi Portal