Cross-Site Scripting Vulnerability in Portabilis i-Educar Software
CVE-2025-8365
5.1MEDIUM
What is CVE-2025-8365?
A vulnerability has been identified in Portabilis i-Educar 2.10 that allows attackers to execute malicious scripts in the context of a user's session. This occurs via improper handling of user-supplied inputs in the atendidos_cad.php file, specifically through the nome, nome_social, and email parameters. The flaw makes the application susceptible to cross-site scripting attacks which may be launched remotely, potentially compromising user data and security. Despite attempts to inform the vendor regarding this matter, no response has been received.
Affected Version(s)
i-Educar 2.10