Portabilis i-Educar Authorization Bypass Vulnerability in API Endpoint

Vulnerability

A Broken Function Level Authorization vulnerability has been identified in Portabilis i-Educar versions through 2.9.0. This issue resides in the API Endpoint '/module/Api/Diario', where proper authorization checks are not enforced. As a result, unauthorized users can remotely access the endpoint and modify student grades, leading to significant integrity issues in academic records.

Impact

Exploitation of this vulnerability allows unauthorized users to alter student grades, bypassing all permission controls. This manipulation of academic data could result in severe integrity issues, with potential legal and reputational consequences for educational institutions.

Reproduction

To reproduce this vulnerability, create a new user account with no privileges. Once the account is set up, send a request to the '/module/Api/Diario' endpoint using the cookie from the low-privilege user. Include the data for the grade to be changed. The request will be processed successfully, indicating that the grade has been altered.

Added: Aug 10, 2025, 3:18 AM
Updated: Aug 10, 2025, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
9.5
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.