Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Bandoler0

#46652de 53,635
5.4CVSS total
Vulnerabilidades · 1
PT-2023-32190
5.4
2023-10-14
Portabilis · Portabilis I-Educar · CVE-2023-5578
**Name of the Vulnerable Software and Affected Versions** Portábilis i-Educar versions up to 2.7.5 **Description** A vulnerability was found in the HTTP GET Request Handler component, specifically in the file intranetagenda imprimir.php. The manipulation of the `cod agenda` argument with malicious input leads to cross-site scripting. The attack can be launched remotely. The exploit has been disclosed to the public. **Recommendations** For versions up to 2.7.5, consider disabling the `cod agenda` argument in the HTTP GET Request Handler to minimize the risk of exploitation until a patch is available. Restrict access to the intranetagenda imprimir.php file to prevent remote attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.