CVE-2025-8539
A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unknown functionality of the file /intranet/public_distrito_cad.php. The manipulation of the argument nome leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.29%
- CWE
- CWE-79, CWE-94
- Published
- 2025-08-05
- Last modified
- 2026-09-15
Affected products
- Portabilis i-Educar
- Portabilis i-Educar
Weakness type
Related vulnerabilities
- CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body
- CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
- CVE-2026-89256 — AVideo Bookmark Plugin Stored XSS via Chapter Names
- CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key
- CVE-2026-89254 — AVideo CustomizeUser Stored XSS via field_name Parameter
- CVE-2026-89253 — AVideo Stored XSS via donationLink in watch page button
- CVE-2026-89249 — AVideo YPTWallet Stored XSS via CryptoWallet Configuration