Portabilis i-Educar Broken Access Control Vulnerability in Enrollment History Endpoint

Vulnerability

A broken access control vulnerability has been identified in Portabilis i-Educar versions through 2.10. The issue resides in the enrollment history endpoint, where improper access controls allow low-privileged users to access restricted functionalities. This vulnerability can be exploited remotely, bypassing authorization checks and potentially leading to unauthorized actions within the application.

Impact

Exploitation of this vulnerability allows low-privileged users to access functionalities reserved for higher-privileged users, such as batch unassigning students from classes. This unauthorized access could disrupt class management and student record integrity.

Reproduction

To reproduce this vulnerability, authenticate as a low-privileged user and send a GET request to the enrollment history endpoint, including the appropriate session cookie. The response will grant access to restricted functionalities that the user should not have.

Added: Sep 17, 2025, 7:22 PM
Updated: Sep 17, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.