Metrics
Affected Vendors & Products
Thu, 09 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
Title | Portabilis i-Educar User Type AccessLevelController.php insecure inherited permissions | |
Weaknesses | CWE-266 CWE-277 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-09T20:35:00.615Z
Reserved: 2025-10-09T11:59:38.265Z
Link: CVE-2025-11554

Updated: 2025-10-09T20:34:54.718Z

Status : Received
Published: 2025-10-09T20:15:37.160
Modified: 2025-10-09T20:15:37.160
Link: CVE-2025-11554

No data.

No data.