VYPR

Pi Portal

by Primakon

CVEs (7)

  • CVE-2025-64063CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the…

  • CVE-2025-64065HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticated low-privileged user to…

  • CVE-2025-64064HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator…

  • CVE-2025-64062HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume…

  • CVE-2025-64066HigNov 25, 2025
    risk 0.56cvss 8.6epss 0.00

    Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the…

  • CVE-2025-64067MedNov 25, 2025
    risk 0.34cvss 5.3epss 0.00

    Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access the requested object or…

  • CVE-2025-64061MedNov 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can make a GET request to this…