CVE-2026-25810 - PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts

CVE-2026-25810 - PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts

CVE ID : CVE-2026-25810 Published : Feb. 9, 2026, 9:15 p.m. | 1 hour, 7 minutes ago Description : PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 9, 2026