A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. The attack can be executed remotely. The exploit has been made public and could be used.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://vuldb.com/?id.321787 | vdb entry |
https://vuldb.com/?ctiid.321787 | signature permissions required |
https://vuldb.com/?submit.636580 | third party advisory |
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9609.md | related |
https://github.com/marcelomulder/CVE/blob/main/i-educar/Broken%20Access%20Control%20%E2%80%93%20Missing%20Function-Level%20Access%20Control%20in%20%60.educacenso.consulta%60%20Endpoint.md#poc | exploit |