Cross-Site Scripting Vulnerability in Portabilis i-Diario Product
CVE-2025-9104

5.1MEDIUM

Key Information:

Vendor

Portabilis

Status
Vendor
CVE Published:
18 August 2025

What is CVE-2025-9104?

A vulnerability has been identified in the Portabilis i-Diario application up to version 1.5.0, specifically affecting the functionality of the /planos-de-aulas-por-disciplina/ page. This issue arises from improper handling of user-supplied input in the parameters related to Parecer/Objeto de Conhecimento/Habilidades, leading to the potential for cross-site scripting (XSS) attacks. Attackers can exploit this vulnerability remotely to inject malicious scripts, which could compromise user interactions and data security. Although the vendor was notified of this vulnerability, there has been no available response or patch to address the threat.

Affected Version(s)

i-Diario 1.0

i-Diario 1.1

i-Diario 1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

marceloQz (VulDB User)
.
CVE-2025-9104 : Cross-Site Scripting Vulnerability in Portabilis i-Diario Product