CVE-2025-10608
BaseFortify
Publication date: 2025-09-17
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| portabilis | i-educar | to 2.10.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Portabilis i-Educar up to version 2.10, specifically in an unknown function within the /enrollment-history/ file. It allows an attacker to bypass proper access controls, potentially enabling unauthorized access. The attack can be performed remotely, and an exploit is publicly available.
How can this vulnerability impact me? :
The vulnerability can lead to improper access control, which may allow unauthorized users to access sensitive enrollment history data or other protected information. This could result in data exposure, data manipulation, or other security breaches affecting confidentiality, integrity, and availability.