CVE-2025-10073 Overview
CVE-2025-10073 is a Broken Object Level Authorization (BOLA) vulnerability affecting Portabilis i-Educar versions up to 2.10. The flaw resides in an unspecified function of the /module/Api/turma endpoint. An authenticated attacker with low privileges can manipulate object identifiers to access class (turma) information belonging to other users or entities. The vulnerability is remotely exploitable over the network and a public proof-of-concept has been disclosed. i-Educar is an open-source school management platform widely used by Brazilian public education institutions, making unauthorized access to class records a privacy concern for student data.
Critical Impact
Authenticated remote attackers can enumerate class information through the /module/Api/turma endpoint due to missing object-level authorization checks, leading to unauthorized disclosure of educational records.
Affected Products
- Portabilis i-Educar versions up to and including 2.10
- CPE: cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:*
- Vulnerable component: /module/Api/turma API endpoint
Discovery Timeline
- 2025-09-08 - CVE-2025-10073 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-10073
Vulnerability Analysis
The vulnerability is classified under [CWE-266: Incorrect Privilege Assignment] and manifests as a Broken Object Level Authorization issue. The /module/Api/turma endpoint exposes class-related data but fails to verify whether the requesting user is authorized to access the referenced object. An attacker with valid low-privilege credentials can iterate through object identifiers to enumerate class information that should be restricted. Because i-Educar handles student and academic data, unauthorized enumeration exposes personally identifiable information tied to educational records. The public disclosure of a proof-of-concept increases the likelihood of opportunistic exploitation against internet-exposed installations.
Root Cause
The root cause is missing authorization enforcement at the object level within the turma (class) API handler. The application authenticates the user session but does not validate that the authenticated principal owns or has been granted access to the requested resource identifier. This gap allows horizontal privilege escalation across class records.
Attack Vector
An attacker requires network access to the i-Educar application and a valid low-privilege account. Exploitation involves issuing crafted HTTP requests to /module/Api/turma with modified object identifiers to enumerate records that belong to other users. No user interaction is required and the attack complexity is low. Refer to the GitHub PoC Repository for technical details of the disclosed proof-of-concept.
// No verified exploit code is reproduced here.
// See the linked GitHub PoC repository for reproduction steps.
Detection Methods for CVE-2025-10073
Indicators of Compromise
- Repeated HTTP requests to /module/Api/turma with sequential or enumerated identifier parameters from a single authenticated session.
- Anomalous volumes of successful responses to turma API calls originating from low-privilege user accounts.
- Access to class records outside the scope of the authenticated user's assigned entities or schools.
Detection Strategies
- Enable verbose application logging on the i-Educar API layer and alert on identifier enumeration patterns against /module/Api/turma.
- Compare requested object IDs against the authenticated user's authorized object scope and flag mismatches.
- Deploy a web application firewall (WAF) rule to rate-limit and inspect requests targeting the turma API endpoint.
Monitoring Recommendations
- Baseline normal API usage per user role and alert on deviations, especially sequential ID access patterns.
- Ingest i-Educar web server and application logs into a centralized analytics platform for correlation.
- Monitor authentication logs for newly created low-privilege accounts followed by high-volume API activity.
How to Mitigate CVE-2025-10073
Immediate Actions Required
- Restrict network exposure of i-Educar deployments to trusted networks or VPN-only access until a patched version is deployed.
- Audit user accounts and disable inactive or unnecessary low-privilege accounts that could be leveraged for authenticated exploitation.
- Review recent access logs for /module/Api/turma requests to identify potential unauthorized enumeration activity.
Patch Information
At the time of publication, no vendor advisory URL is listed in the NVD entry. Administrators should monitor the Portabilis i-Educar GitHub project for security updates beyond version 2.10 and apply object-level authorization fixes as they become available. Consult the VulDB #323021 entry for updates on remediation status.
Workarounds
- Implement WAF or reverse-proxy rules that enforce identifier scope validation for requests to /module/Api/turma.
- Apply network-level access controls limiting API access to authenticated internal users only.
- Reduce the privileges of application accounts to the minimum required and segment school data by tenant where possible.
# Example nginx rule to log and rate-limit access to the vulnerable endpoint
location /module/Api/turma {
limit_req zone=api_turma burst=5 nodelay;
access_log /var/log/nginx/turma_api.log combined;
proxy_pass http://i_educar_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
