PT-2025-9830 · Unknown · Pik Online

Mucahit Ic

·

Published

2025-03-05

·

Updated

2025-08-19

·

CVE-2024-11216

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Pik Online versions through 05.03.2025
Description The issue allows for Authorization Bypass Through User-Controlled Key and Exposure of Private Personal Information to an unauthorized actor. This can lead to Account Footprinting and Session Hijacking. The vendor was contacted about this disclosure but did not respond.
Recommendations For versions through 05.03.2025, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-11216

Affected Products

Pik Online