PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Praskla-technology
Praskla-technology assessment-placipy |
|
| Vendors & Products |
Praskla-technology
Praskla-technology assessment-placipy |
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known. | |
| Title | PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover) | |
| Weaknesses | CWE-259 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-06T18:57:31.419Z
Updated: 2026-02-09T15:28:38.433Z
Reserved: 2026-02-05T18:35:52.357Z
Link: CVE-2026-25753
No data.
Status : Awaiting Analysis
Published: 2026-02-06T19:16:10.473
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-25753
No data.