PT-2025-32463 · Unknown · Portabilis I-Educar

Natan Morette

+1

·

Published

2025-08-10

·

Updated

2025-08-13

·

CVE-2025-8790

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Portabilis i-Educar versions up to 2.9.0
Description: A critical issue exists in Portabilis i-Educar related to improper authorization. The vulnerability is located in the API Endpoint component, specifically within the /module/Api/pessoa file. Manipulation of the ID argument can lead to unauthorized access. The exploit is publicly available and can be initiated remotely. The vendor was informed of this issue but did not provide a response.
Recommendations: Versions prior to 2.9.0: Address improper authorization by validating the ID argument in the /module/Api/pessoa API Endpoint.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-8790

Affected Products

Portabilis I-Educar