Aller au contenu

Fiche vulnérabilité

CVE-2025-10099 : faille moyenne portabilis i-educar (CVSS 4.8)

Description

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of the component Editar usuário Page. This manipulation of the argument email/data_inicial/data_expiracao causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

En bref

Sévérité
Moyenne (CVSS 4.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
8 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • portabilis i-educar

Références

Rechercher une autre vulnérabilité dans la base CVE