Impact
The vulnerability in Version 1.0.0 of the PlaciPy placement management system causes the application to write highly sensitive data directly to console output without any masking or redaction. This results in the accidental disclosure of confidential information to anyone with access to the logs, allowing an attacker to read personal or institutional data that should remain private.
Affected Systems
Praskla-Technology’s assessment-placipy product, Version 1.0.0, is impacted by this flaw.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, reflecting a high severity level. The Current Exploit Prediction Scoring System (EPSS) score is below 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector could involve local access to the application console or remote exploitation of another vulnerability that grants read access to console output; however, explicit details are not provided in the advisory.
OpenCVE Enrichment