Executive brief
Pik Online, a software solution by Pik Online Yazılım Çözümleri A.Ş., is affected by a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers or keys, an attacker can bypass security checks to view data they are not permitted to see. This could lead to the exposure of confidential customer or business information. Users should update to version 3.1.5 or later to resolve this issue.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in Pik Online versions prior to 3.1.5. The flaw occurs when the application uses client-supplied input to access objects or records without sufficiently verifying that the requesting user has the necessary permissions for that specific identifier. A remote, unauthenticated attacker can exploit this by modifying parameters (such as IDs in a URL or API request) to access data belonging to other users or the system. The vulnerability is exploitable over the network with low complexity and requires no user interaction. A patch is available in version 3.1.5.
Affected products
- Pik Online Yazılım Çözümleri A.Ş. Pik Online before 3.1.5
Timeline
- 2025-08-20: disclosed
- 2025-08-20: advisory