Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: before 3.1.5.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.usom.gov.tr/bildirim/tr-25-0052 |     | 
History
                    Tue, 19 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: through 05.03.2025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: before 3.1.5. | 
Wed, 05 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 05 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: through 05.03.2025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Broken Access Control in PozitifIK's Pik Online | |
| Weaknesses | CWE-359 CWE-639 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: TR-CERT
Published: 2025-03-05T13:02:20.755Z
Updated: 2025-08-19T14:15:58.924Z
Reserved: 2024-11-14T11:55:36.558Z
Link: CVE-2024-11216
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-05T14:07:36.379Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-03-05T13:15:11.493
Modified: 2025-08-19T15:15:26.807
Link: CVE-2024-11216
 Redhat
                        Redhat
                    No data.