PT-2024-33082 · Portabilis · Portabilis I-Educar

Published

2024-11-02

·

Updated

2024-11-02

·

CVE-2024-48326

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar version 2.9.0
Description The issue concerns a Cross-Site Scripting (XSS) vulnerability. It can be exploited via the nm religiao parameter in the "/intranet/educar religiao lst.php?busca=S&nm religiao=" endpoint.
Recommendations For Portabilis i-Educar version 2.9.0, consider restricting access to the vulnerable endpoint "/intranet/educar religiao lst.php" to minimize the risk of exploitation. Avoid using the nm religiao parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2024-48326

Affected Products

Portabilis I-Educar