📦 Project Contract Management

by Primakon

🔍 What is Project Contract Management?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64064

HIGH CVSS 8.8 Nov 25, 2025

Primakon Pi Portal 1.0.18 has an insecure direct object reference vulnerability in its /api/v2/pp_users endpoint that allows any authenticated user to escalate privileges to administrator. This affect...

CVE-2025-64065

HIGH CVSS 8.8 Nov 25, 2025

This vulnerability allows any authenticated low-privileged user in Primakon Pi Portal to impersonate any other user, including administrators, by exploiting broken authorization in the user impersonat...

CVE-2025-64066

HIGH CVSS 8.6 Nov 25, 2025

Primakon Pi Portal 1.0.18 has a broken access control vulnerability in its user registration endpoint that allows unauthenticated attackers to create new user accounts in the local database. This bypa...

CVE-2025-64061

MEDIUM CVSS 4.3 Nov 25, 2025

Primakon Pi Portal 1.0.18's /api/v2/users endpoint lacks proper access controls, allowing any authenticated user to retrieve a complete list of all registered users including their password hashes. Th...