Executive brief
DijiDemi, an educational and publishing platform, contains a security flaw that allows users to bypass authorization controls. By manipulating specific identifiers or keys, an attacker can gain access to data or functions they are not permitted to use. This could lead to unauthorized access to sensitive educational records or administrative functions, potentially compromising the integrity of the platform's data.
Technical details
An authorization bypass vulnerability (CWE-639) exists in DijiDemi versions v4.5.12.1 through v4.5.13.0. The flaw stems from the application's reliance on user-controlled keys to perform authorization checks, allowing an attacker to access or modify records belonging to other users by manipulating these keys. Exploitation requires high privileges and some user interaction, but it allows for a significant impact on confidentiality, integrity, and availability. The vulnerability is addressed in version 4.5.13.0.
Affected products
- Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi v4.5.12.1 before v4.5.13.0
Timeline
- 2026-05-14: advisory: NVD published the CVE record based on TR-CERT data.
- 2026-05-14: disclosed: Initial disclosure by the Computer Emergency Response Team of the Republic of Turkey.