PT-2025-35447 · Portabilis · Portabilis I-Educar

Marceloqz

·

Published

2025-09-01

·

Updated

2025-09-27

·

CVE-2025-9760

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar versions up to 2.10
Description A weakness exists in the Matricula API component of Portabilis i-Educar. The issue affects an unknown part of the file /module/Api/aluno. Manipulation of this component can lead to improper authorization. The attack can be launched remotely, and the exploit has been made publicly available.
Recommendations Versions prior to 2.10 should be updated. As a temporary workaround, restrict access to the /module/Api/aluno file to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-9760

Affected Products

Portabilis I-Educar