PT-2025-32458 · Portabilis · I-Educar
Marceloqz
·
Published
2025-08-09
·
Updated
2025-08-10
·
CVE-2025-8785
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Portabilis i-Educar versions up to 2.9
Description:
A cross site scripting issue exists due to the manipulation of the
nm pessoa/matricula/matricula interna argument in the processing of the /intranet/educar usuario lst.php file. The attack can be initiated remotely. The exploit has been publicly disclosed.Recommendations:
Versions prior to 2.9: Address the improper handling of the
nm pessoa/matricula/matricula interna argument in the /intranet/educar usuario lst.php file to prevent cross site scripting.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
I-Educar