CVE-2025-10607
BaseFortify
Publication date: 2025-09-17
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| portabilis | i-educar | to 2.10.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Portabilis i-Educar up to version 2.10, specifically in an unknown function within the file /module/Avaliacao/diarioApi. It allows an attacker to remotely manipulate the system, leading to information disclosure. The exploit has been publicly disclosed and can be used by attackers.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized information disclosure, meaning sensitive data could be exposed to attackers. Since the attack can be executed remotely, it increases the risk of data leakage without physical access to the system.