Cross-Site Scripting Vulnerability in Portabilis i-Diario Product
CVE-2025-9104
5.1MEDIUM
What is CVE-2025-9104?
A vulnerability has been identified in the Portabilis i-Diario application up to version 1.5.0, specifically affecting the functionality of the /planos-de-aulas-por-disciplina/ page. This issue arises from improper handling of user-supplied input in the parameters related to Parecer/Objeto de Conhecimento/Habilidades, leading to the potential for cross-site scripting (XSS) attacks. Attackers can exploit this vulnerability remotely to inject malicious scripts, which could compromise user interactions and data security. Although the vendor was notified of this vulnerability, there has been no available response or patch to address the threat.
Affected Version(s)
i-Diario 1.0
i-Diario 1.1
i-Diario 1.2