Description
Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_estado=T&wAccion=listado_xlsx&wBuscar=&wFiltrar=&wOrden=alta_usuario&wid_cursoActual=[ID]' where the data of users enrolled in the course is exported. Successful exploitation of this vulnerability could allow an unauthenticated attacker to access user data (e.g., usernames, first and last names, email addresses, and phone numbers) and retrieve the data of all users enrolled in courses by performing a brute-force attack on the course ID via a manipulated URL.
Published: 2026-03-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted Data Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference that allows an unauthenticated attacker to download an Excel file containing usernames, full names, email addresses and phone numbers of all users enrolled in a course. This data exposure constitutes a breach of confidentiality and is mapped to CWE‑284, missing access control.

Affected Systems

Affected is the Educativa Campus application. The vulnerable version reported is 14.05.00-35; the fix is available in 14.05.00-159 and later. Versions older than the fix are likely impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower immediate risk of widespread exploitation. However, because the vulnerable endpoint is accessible without authentication and accepts a course identifier as a query parameter, an attacker can brute‑force course IDs to enumerate and retrieve user data. The exploit is straightforward once the target URL is known, making it potentially attractive to attackers who wish to harvest personal information.

Generated by OpenCVE AI on March 22, 2026 at 14:48 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed by Educativa team in version 14.05.00-159 and latest.


OpenCVE Recommended Actions

  • Apply Educativa Campus version 14.05.00‑159 or newer to eliminate the IDOR.
  • If patch deployment cannot occur immediately, limit or block access to the /administracion/admin_usuarios.cgi endpoint, or implement rate‑limiting to prevent automated course–ID enumeration.

Generated by OpenCVE AI on March 22, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
Description Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_estado=T&wAccion=listado_xlsx&wBuscar=&wFiltrar=&wOrden=alta_usuario&wid_cursoActual=[ID]' where the data of users enrolled in the course is exported. Successful exploitation of this vulnerability could allow an unauthenticated attacker to access user data (e.g., usernames, first and last names, email addresses, and phone numbers) and retrieve the data of all users enrolled in courses by performing a brute-force attack on the course ID via a manipulated URL.
Title Multiple vulnerabilities on the Educativa Campus
First Time appeared Educativa
Educativa campus
Weaknesses CWE-284
CPEs cpe:2.3:a:educativa:campus:14.05.00-35:*:*:*:*:*:*:*
Vendors & Products Educativa
Educativa campus
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Educativa Campus
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-03-16T18:58:35.727Z

Reserved: 2026-02-24T10:54:34.006Z

Link: CVE-2026-3110

cve-icon Vulnrichment

Updated: 2026-03-16T18:58:31.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T14:19:46.907

Modified: 2026-03-16T14:53:07.390

Link: CVE-2026-3110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T07:02:55Z

Weaknesses