Vulnerability Description
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can make a GET request to this endpoint and retrieve a complete, unfiltered list of all registered application users. Crucially, the API response body for this endpoint includes password hashes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Primakon | Project Contract Management | 1.0.18 |
Related Weaknesses (CWE)
References
- https://github.com/n3k7ar91/Vulnerabilites/blob/main/Primakon/CVE-2025-64061.mdThird Party Advisory
- https://www.primakon.com/rjesenja/primakon-pcm/Product
FAQ
What is CVE-2025-64061?
CVE-2025-64061 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (in...
How severe is CVE-2025-64061?
CVE-2025-64061 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64061?
Check the references section above for vendor advisories and patch information. Affected products include: Primakon Project Contract Management.