PT-2025-31480 · Unknown · Portabilis I-Educar

Marceloqz

·

Publicado

2025-07-31

·

Atualizado

2025-07-31

·

CVE-2025-8370

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar version 2.9
Description A problematic issue exists in Portabilis i-Educar 2.9. The vulnerability is located in the /intranet/educar escolaridade lst.php file. Manipulation of the descricao parameter can lead to cross-site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be used. The vendor was contacted but did not respond.
Recommendations As a mitigation, consider restricting or disabling access to the /intranet/educar escolaridade lst.php file. Avoid using the descricao parameter in the affected file until the issue is resolved.

Exploit

Correção

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8370

Produtos afetados

Portabilis I-Educar