CVE-2025-10072
Last modified
CVE-2025-10072 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.11.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described improper access control behavior could no longer be reproduced."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Portabilis | I-Educar | <= 2.10.0 |
References
- https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10072.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-10072?
How severe is CVE-2025-10072?
How do I fix CVE-2025-10072?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10066A security vulnerability has been detected in itsourcecode P…6.1
- CVE-2025-10067A vulnerability was detected in itsourcecode POS Point of Sa…6.1
- CVE-2025-10068A flaw has been found in itsourcecode Online Discussion Foru…9.8
- CVE-2025-1007In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{…5.3
- CVE-2025-10070A flaw has been found in Portabilis i-Educar up to 2.10. Thi…6.3
- CVE-2025-10071A vulnerability has been found in Portabilis i-Educar up to …6.3
- CVE-2025-10073A vulnerability was determined in Portabilis i-Educar up to …4.3
- CVE-2025-10074A vulnerability was identified in Portabilis i-Educar up to …5.4
- CVE-2025-10075A security flaw has been discovered in SourceCodester Online…5.4
- CVE-2025-10076A weakness has been identified in SourceCodester Online Poll…9.8
- CVE-2025-10077A security vulnerability has been detected in SourceCodester…9.8
- CVE-2025-10078A vulnerability was detected in SourceCodester Online Pollin…9.8
Are you affected by CVE-2025-10072?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
