CVE-2024-11216: Pozitifik Pik Online

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking. This issue affects Pik Online: before 3.1.5.

Affected products

  • Pozitifik Pik Online: before 3.1.5 (fixed in 3.1.5)

Published 2025-03-05. Last modified 2026-06-17.