PT-2025-35356 · Unknown · Portabilis I-Educar
Marceloqz
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9687
Marceloqz
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9687
6.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Portabilis i-Educar versions prior to 2.11
Description:
A weakness exists in Portabilis i-Educar up to version 2.10 due to improper authorization. This issue is related to an unknown function within the `/module/HistoricoEscolar/processamentoApi` file. The attack can be performed remotely. The exploit has been made publicly available.
Recommendations:
Update Portabilis i-Educar to version 2.11 or later.
As a temporary workaround, restrict access to the `/module/HistoricoEscolar/processamentoApi` file.
Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization