Junglewise Threat Intelligence

CVE-2025-5260: Pik Online Yazılım Çözümleri Pik Online SSRF

CVE-2025-5260 · Severity: high · CVSS 8.6 · Published 2025-08-20

Executive brief

Pik Online, a software solution from Pik Online Yazılım Çözümleri A.Ş., is vulnerable to a security flaw that allows attackers to trick the server into making unauthorized requests. This could allow an attacker to access sensitive internal data, bypass security controls, or interact with other internal systems that are not intended to be public. Organizations using versions prior to 3.1.5 should update immediately to prevent potential data exposure or unauthorized internal network access.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Pik Online versions prior to 3.1.5. The flaw (CWE-918) allows a remote, unauthenticated attacker to send specially crafted network requests from the vulnerable server. By exploiting this, an attacker can potentially scan internal networks, access metadata services, or interact with internal APIs that are otherwise unreachable from the public internet. The vulnerability is rated with a CVSS score of 8.6, indicating high impact on confidentiality. Users are advised to upgrade to version 3.1.5 or later to mitigate this risk.

Affected products

  • Pik Online Yazılım Çözümleri A.Ş. Pik Online before 3.1.5

Timeline

  • 2025-08-20: advisory: Initial publication of CVE-2025-5260
  • 2026-06-05: other: NVD record modified

References

Related threats