CVE-2025-9760
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
Vendor
Product
CWE
Yayın Tarihi
2025-09-01 05:15:41
Güncelleme
2025-09-27 00:28:31
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/marcelomulder/CVE/blob/main/i-educar/Broken%20Function%20Level%20Authorization%20on%20%60matricula%60%20API%20allows%20deletion%20of%20%E2%80%9Cabandono%E2%80%9D%20status.md#proof-of-concept-poc
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9760.md
https://vuldb.com/?ctiid.322061
https://vuldb.com/?id.322061
https://vuldb.com/?submit.640690
https://vuldb.com/?submit.643575
https://vuldb.com/?submit.648827
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9760.md