Impact
The vulnerability occurs in PlaciPy’s code evaluation endpoint, which fails to enforce checks on the assessment lifecycle state. Users can invoke the endpoint regardless of whether an assessment has started, expired, or has an open submission window. This permissive behavior allows execution of arbitrary code on the server platform, constituting an authorization flaw that can compromise application integrity and confidentiality.
Affected Systems
The affected system is Praskla‑Technology’s placement management application, PlaciPy, version 1.0.0. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 signifies moderate severity, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. It is most likely to be exploited remotely through the exposed code evaluation endpoint, provided an attacker can submit code payloads, but no persistent exploitation evidence currently exists.
OpenCVE Enrichment