CVE-2026-25753 PUBLISHED

PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)

Assigner: GitHub_M
Reserved: 05.02.2026 Published: 06.02.2026 Updated: 06.02.2026

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Praskla-Technology
Product assessment-placipy
Versions
  • Version <= 1.0.0 is affected

References

Problem Types

  • CWE-259: Use of Hard-coded Password CWE