A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/m3m0o/portabilis-ieducar-user-type-privilege-escalation | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.327714 | Permissions Required VDB Entry |
| https://vuldb.com/?id.327714 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.671072 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2025, 15:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/m3m0o/portabilis-ieducar-user-type-privilege-escalation - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.327714 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.327714 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.671072 - Third Party Advisory, VDB Entry | |
| First Time |
Portabilis i-educar
Portabilis |
|
| CPE | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* |
11 Oct 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
09 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-09 20:15
Updated : 2025-11-21 15:07
NVD link : CVE-2025-11554
Mitre link : CVE-2025-11554
CVE.ORG link : CVE-2025-11554
JSON object : View
Products Affected
portabilis
- i-educar
