Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2 inside body of request and escalate privileges.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 01 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Primakon project Contract Management
|
|
| CPEs | cpe:2.3:a:primakon:project_contract_management:1.0.18:*:*:*:*:*:*:* | |
| Vendors & Products |
Primakon project Contract Management
|
Thu, 27 Nov 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Primakon
Primakon pi Portal |
|
| Vendors & Products |
Primakon
Primakon pi Portal |
Tue, 25 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2 inside body of request and escalate privileges. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-25T20:35:12.049Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64064
No data.
Status : Analyzed
Published: 2025-11-25T19:15:50.500
Modified: 2025-12-01T14:22:20.960
Link: CVE-2025-64064
No data.
OpenCVE Enrichment
Updated: 2025-11-27T09:45:22Z
Weaknesses