CVE-2025-5260

8.6

Pik Online Yazılım Çözümleri A.Ş. · Pik Online

A Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows unauthenticated attackers to perform unauthorized requests.

Executive summary

A critical Server-Side Request Forgery vulnerability in Pik Online allows unauthenticated attackers to potentially access internal resources or perform unauthorized requests, posing a significant security risk.

Vulnerability

The application is susceptible to CWE-918: Server-Side Request Forgery (SSRF) due to improper input validation, which allows an unauthenticated remote attacker to force the server to make requests to arbitrary destinations.

Business impact

Successful exploitation of this SSRF vulnerability may allow attackers to bypass network access controls, interact with internal services that are not exposed to the internet, or perform port scanning of the internal infrastructure. Given the CVSS score of 8.6, this flaw is categorized as High severity and could lead to unauthorized data disclosure or service disruption within the internal network environment.

Remediation

Immediate Action: Update the Pik Online software to version 3.1.5 or the latest available version provided by the vendor.

Proactive Monitoring: Monitor network traffic for suspicious outbound requests originating from the application server and review system access logs for anomalous behavior.

Compensating Controls: Implement strict egress filtering on the application server to restrict outbound connections to only necessary internal or external endpoints until the software is updated.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Organizations utilizing Pik Online should prioritize upgrading to version 3.1.5 to eliminate this SSRF vulnerability. Given the ease of automation for this type of flaw, it is critical to address this vulnerability immediately to prevent potential reconnaissance or unauthorized access to internal network resources.

More Pik Online Yazılım Çözümleri A.Ş. CVEs

Sources

Originally found and disclosed by Mustafa Anıl YILDIRIM, Cem YURTDAŞ, per the CVE Program record.