Portabilis i-Educar Improper Authorization Vulnerability in the HistoricoEscolar Module

Vulnerability

A vulnerability allowing improper authorization has been identified in Portabilis i-Educar versions through 2.10. The issue resides in the '/module/HistoricoEscolar/processamentoApi' endpoint, where the application fails to enforce proper object-level authorization. This flaw enables low-privileged users, such as standard student or responsible accounts, to access unauthorized enrollment information of other students, thereby exposing Personally Identifiable Information (PII) without appropriate authorization checks. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows unauthorized access to sensitive student information, including names, enrollment details, and institutional relationships. This could lead to privacy violations, unauthorized data harvesting across institutions, social engineering opportunities, and reputational damage for the affected institution.

Reproduction

To reproduce this vulnerability, authenticate as a low-privileged user and send a GET request to the '/module/HistoricoEscolar/processamentoApi' endpoint. Include parameters such as 'att' set to 'matriculas', 'oper' set to 'get', and other relevant identifiers for the institution, school, course, series, and class. The request must be made with an active session cookie for the low-privileged user.

Added: Aug 30, 2025, 12:21 PM
Updated: Aug 30, 2025, 12:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
6.2
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.