CVE-2025-10070
BaseFortify
Publication date: 2025-09-07
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| portabilis | i-educar | to 2.10.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a flaw in Portabilis i-Educar up to version 2.10, specifically related to an unknown part of the file /enturmacao-em-lote/. It causes improper access controls, allowing an attacker to potentially access resources or data they should not be able to. The attack can be carried out remotely, and an exploit has already been published.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access due to improper access controls, which may result in exposure or manipulation of sensitive data or system functions. Since the attack can be performed remotely and an exploit is publicly available, it increases the risk of compromise if the system is not patched or mitigated.