Description
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Es wurde eine Schwachstelle in Portabilis i-Educar up to 2.10 entdeckt. Betroffen ist eine unbekannte Funktion der Datei /consulta-dispensas. Die Manipulation führt zu improper authorization. Ein Angriff ist aus der Distanz möglich. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Incorrect Privilege Assignment
Product status
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2.10
Timeline
2025-09-26: | Advisory disclosed |
2025-09-26: | VulDB entry created |
2025-09-26: | VulDB entry last update |
Credits
marceloQz (VulDB User)
marceloQz (VulDB User)
References
vuldb.com/?id.326085 (VDB-326085 | Portabilis i-Educar consulta-dispensas improper authorization)
vuldb.com/?ctiid.326085 (VDB-326085 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.659202 (Submit #659202 | Portabilis i-educar 2.10 Broken Access Control)
github.com/...ulder/CVE/blob/main/i-educar/CVE-2025-11048.md
github.com/... Control in `.consulta-dispensas` Endpoint.md