CVE-2025-9109

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
References
Link Resource
https://vuldb.com/?ctiid.320431 Permissions Required VDB Entry
https://vuldb.com/?id.320431 Third Party Advisory VDB Entry
https://vuldb.com/?submit.627926 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-18 06:15

Updated : 2025-09-10 14:32


NVD link : CVE-2025-9109

Mitre link : CVE-2025-9109

CVE.ORG link : CVE-2025-9109


JSON object : View

Products Affected

portabilis

  • i-diario
CWE
CWE-203

Observable Discrepancy

CWE-204

Observable Response Discrepancy