Metrics
Affected Vendors & Products
Sat, 11 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 11 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portabilis
Portabilis i-educar |
|
| Vendors & Products |
Portabilis
Portabilis i-educar |
Thu, 09 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Title | Portabilis i-Educar User Type AccessLevelController.php insecure inherited permissions | |
| Weaknesses | CWE-266 CWE-277 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-09T20:02:06.510Z
Updated: 2025-10-11T21:02:09.590Z
Reserved: 2025-10-09T11:59:38.265Z
Link: CVE-2025-11554
Updated: 2025-10-09T20:34:54.718Z
Status : Awaiting Analysis
Published: 2025-10-09T20:15:37.160
Modified: 2025-10-14T19:37:28.107
Link: CVE-2025-11554
No data.