CVE-2025-11047: Portabilis i-Educar aluno improper authorization
Published Sep 26, 2025
·Updated
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument alunoid causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
2 affected components
Portabilis i-Educar<=2.10
Portabilis i-Educar<=2.10.0
Event History
Sep 26, 2025
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11047?
CVE-2025-11047 is considered a medium severity vulnerability due to improper authorization in Portabilis i-Educar.
2
How do I fix CVE-2025-11047?
To fix CVE-2025-11047, upgrade Portabilis i-Educar to a version higher than 2.10.
3
What impact does CVE-2025-11047 have on Portabilis i-Educar?
CVE-2025-11047 can allow an unauthorized user to manipulate the aluno_id argument and exploit the system.
4
Is the CVE-2025-11047 vulnerability exploitable remotely?
Yes, CVE-2025-11047 can be exploited remotely.
5
Which versions of Portabilis i-Educar are affected by CVE-2025-11047?
Portabilis i-Educar versions up to and including 2.10 are affected by CVE-2025-11047.