Stored Cross-Site Scripting Vulnerability in i-Educar School Management Software
CVE-2024-55651

2LOW

Key Information:

Vendor

Portabilis

Status
Vendor
CVE Published:
8 May 2025

What is CVE-2024-55651?

The i-Educar school management software, specifically in version 2.9, contains a flaw in its handling of user input within the user type field. This weakness allows attackers to insert malicious scripts that are stored and executed in other users' browsers. Consequently, sensitive data belonging to users could be accessed, leading to unauthorized actions and information disclosures. As of the last update, there are no known patches to remediate this vulnerability, leaving users exposed to potential exploitation.

Affected Version(s)

i-educar = 2.9

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

.