CVE-2024-45058
Last modified
CVE-2024-45058 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to Administrator (or another type with super-permissions) through a specifically crafted POST request to `/intranet/educar_usuario_cad.php`, modifying the `nivel_usuario_` parameter. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to Administrator (or another type with super-permissions) through a specifically crafted POST request to `/intranet/educar_usuario_cad.php`, modifying the `nivel_usuario_` parameter. The vulnerability occurs in the file located at `ieducar/intranet/educar_usuario_cad.php`, which does not check the user's current permission level before allowing changes. Commit c25910cdf11ab50e50162a49dd44bef544422b6e contains a patch for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Portabilis | I-Educar | <= 2.9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45058?
How severe is CVE-2024-45058?
How do I fix CVE-2024-45058?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45051Discourse is an open source platform for community discussio…8.2
- CVE-2024-45052Fides is an open-source privacy engineering platform. Prior …5.3
- CVE-2024-45053Fides is an open-source privacy engineering platform. Starti…7.2
- CVE-2024-45054Hwameistor is an HA local storage system for cloud-native st…6.7
- CVE-2024-45056zksolc is a Solidity compiler for ZKsync. All LLVM versions …5.9
- CVE-2024-45057i-Educar is free, fully online school management software th…6.1
- CVE-2024-45059i-Educar is free, fully online school management software th…8.8
- CVE-2024-4506A vulnerability has been found in Ruijie RG-UAC up to 202404…7.2
- CVE-2024-45060PHPSpreadsheet is a pure PHP library for reading and writing…6.1
- CVE-2024-45061A cross-site scripting (xss) vulnerability exists in the wea…5.4
- CVE-2024-45062A stack based buffer overflow vulnerability is present in Op…6.8
- CVE-2024-45063The function ctl_write_buffer incorrectly set a flag which r…8.8
Are you affected by CVE-2024-45058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
