A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
References
Link | Resource |
---|---|
https://vuldb.com/?ctiid.320431 | Permissions Required VDB Entry |
https://vuldb.com/?id.320431 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.627926 | Third Party Advisory VDB Entry |
Configurations
History
10 Sep 2025, 14:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://vuldb.com/?ctiid.320431 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.320431 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.627926 - Third Party Advisory, VDB Entry | |
Summary | (es) Se ha descubierto una falla de seguridad en Portabilis i-Diario (hasta la versión 1.5.0). Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /password/email del componente Password Recovery Endpoint. La manipulación provoca una discrepancia observable en las respuestas. El ataque puede ejecutarse en remoto. Es un ataque de complejidad bastante alta. Parece difícil de explotar. Se ha hecho público el exploit y puede que sea utilizado. | |
CPE | cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:* | |
First Time |
Portabilis
Portabilis i-diario |
18 Aug 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Aug 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-18 06:15
Updated : 2025-09-10 14:32
NVD link : CVE-2025-9109
Mitre link : CVE-2025-9109
CVE.ORG link : CVE-2025-9109
JSON object : View
Products Affected
portabilis
- i-diario