PT-2026-7157 · Placipy · Placipy
Th3Gowham
·
Published
2026-02-09
·
Updated
2026-02-18
·
CVE-2026-25811
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PlaciPy version 1.0.0
Description
PlaciPy is a placement management system for educational institutions. Version 1.0.0 improperly derives the tenant identifier from the user-provided email domain without validating ownership or registration. This flaw enables cross-tenant data access. The application uses the email domain to determine the tenant, potentially allowing a user to access data belonging to another tenant by simply using an email address with a different domain.
Recommendations
Implement proper domain validation to ensure users only have access to data within their registered tenant.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Placipy