CVE-2025-11554
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.38%
- CWE
- CWE-277, CWE-266
- Published
- 2025-10-09
- Last modified
- 2026-03-12
Affected products
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
- Portabilis i-Educar
Weakness type
Related vulnerabilities
- CVE-2026-9046 — A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store...
- CVE-2026-7891 — The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure...
- CVE-2025-32092 — Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0...
- CVE-2025-65111 — SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
- CVE-2025-64185 — Open OnDemand RPM packages create world writable locations
- CVE-2025-24327 — Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before...
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-9039 — Information Disclosure in Amazon ECS Container Agent