CVE-2025-9109

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
Configurations

No configuration.

History

18 Aug 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una falla de seguridad en Portabilis i-Diario (hasta la versión 1.5.0). Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /password/email del componente Password Recovery Endpoint. La manipulación provoca una discrepancia observable en las respuestas. El ataque puede ejecutarse en remoto. Es un ataque de complejidad bastante alta. Parece difícil de explotar. El exploit se ha hecho público y podría ser explotado.

18 Aug 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-18 06:15

Updated : 2025-08-18 20:16


NVD link : CVE-2025-9109

Mitre link : CVE-2025-9109

CVE.ORG link : CVE-2025-9109


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy

CWE-204

Observable Response Discrepancy