Metrics
Affected Vendors & Products
Wed, 10 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:* |
Mon, 18 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portabilis
Portabilis i-diario |
|
| Vendors & Products |
Portabilis
Portabilis i-diario |
Mon, 18 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 Aug 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited. | |
| Title | Portabilis i-Diario Password Recovery Endpoint email observable response discrepancy | |
| Weaknesses | CWE-203 CWE-204 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-18T06:02:06.571Z
Updated: 2025-08-18T15:34:02.189Z
Reserved: 2025-08-17T20:38:06.556Z
Link: CVE-2025-9109
Updated: 2025-08-18T15:33:09.377Z
Status : Analyzed
Published: 2025-08-18T06:15:30.250
Modified: 2025-09-10T14:32:33.513
Link: CVE-2025-9109
No data.