CVE-2025-5260
8.6Pik Online Yazılım Çözümleri A.Ş. · Pik Online
A Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows unauthenticated attackers to perform unauthorized requests.
Executive summary
A critical Server-Side Request Forgery vulnerability in Pik Online allows unauthenticated attackers to potentially access internal resources or perform unauthorized requests, posing a significant security risk.
Vulnerability
The application is susceptible to CWE-918: Server-Side Request Forgery (SSRF) due to improper input validation, which allows an unauthenticated remote attacker to force the server to make requests to arbitrary destinations.
Business impact
Successful exploitation of this SSRF vulnerability may allow attackers to bypass network access controls, interact with internal services that are not exposed to the internet, or perform port scanning of the internal infrastructure. Given the CVSS score of 8.6, this flaw is categorized as High severity and could lead to unauthorized data disclosure or service disruption within the internal network environment.
Remediation
Immediate Action: Update the Pik Online software to version 3.1.5 or the latest available version provided by the vendor.
Proactive Monitoring: Monitor network traffic for suspicious outbound requests originating from the application server and review system access logs for anomalous behavior.
Compensating Controls: Implement strict egress filtering on the application server to restrict outbound connections to only necessary internal or external endpoints until the software is updated.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Organizations utilizing Pik Online should prioritize upgrading to version 3.1.5 to eliminate this SSRF vulnerability. Given the ease of automation for this type of flaw, it is critical to address this vulnerability immediately to prevent potential reconnaissance or unauthorized access to internal network resources.
More Pik Online Yazılım Çözümleri A.Ş. CVEs
Sources
Originally found and disclosed by Mustafa Anıl YILDIRIM, Cem YURTDAŞ, per the CVE Program record.