Cross-Site Scripting Issue in Portabilis i-Educar Software
CVE-2025-10099
What is CVE-2025-10099?
A vulnerability has been identified in the Portabilis i-Educar up to version 2.10, specifically affecting the file /intranet/educar_usuario_cad.php within the Editar usuário Page. This weakness allows attackers to manipulate arguments related to user data, such as email, initial date, and expiration date, thereby enabling remote execution of cross-site scripting (XSS) attacks. Given that exploits have been publicly disclosed, users of the affected versions are at risk of potential data compromise or unauthorized actions within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
i-Educar 2.0
i-Educar 2.1
i-Educar 2.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
