PT-2025-33059 · Portabilis · Portabilis I-Diario

Feemarb

+2

·

Published

2025-08-13

·

Updated

2025-08-13

·

CVE-2025-8919

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Portabilis i-Diario versions prior to 1.7
Description: A cross-site scripting issue exists in Portabilis i-Diario due to manipulation of the código/objetivo habilidade argument within an unknown function of the /objetivos-de-aprendizagem-e-habilidades file of the History Page component. This allows for remote attacks. The exploit has been publicly disclosed.
Recommendations: Update Portabilis i-Diario to version 1.7 or later. As a temporary workaround, restrict or sanitize input to the código/objetivo habilidade argument in the /objetivos-de-aprendizagem-e-habilidades file.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8919

Affected Products

Portabilis I-Diario