PT-2026-6716 · Unknown · Portabilis I-Educar

Vini_Castro

·

Publicado

2026-02-06

·

Atualizado

2026-02-06

·

CVE-2026-2015

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar versions up to 2.10
Description A weakness exists in Portabilis i-Educar up to version 2.10, specifically within the Final Status Import component. The issue involves improper authorization that can be triggered by manipulating the school id argument within an unknown function of the FinalStatusImportService.php file. This manipulation can be executed remotely. The exploit for this issue has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 2.10 should be updated. As a temporary workaround, consider restricting access to the FinalStatusImportService.php file to minimize the risk of exploitation.

Exploit

Correção

Improper Authorization

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2015

Produtos afetados

Portabilis I-Educar