216.73.216.6

CVE-2025-64064

· Published 25/11/2025 19:15 · Modified 01/12/2025 14:22

Labels: CVE-2025-64064 2025-11-25CVE-2025-64064CWE-284[email protected]

Essential information

Published
25/11/2025 19:15
Modified
01/12/2025 14:22
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2 inside body of request and escalate privileges.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
primakon / project contract management cpe:2.3:a:primakon:project_contract_management:1.0.18:*:*:*:*:*:*:*

References