Portabilis i-Educar 2.10 /educar_aluno_lst.php ref_cod_matricula Cross Site Scripting

Hakika vulnerability da aka rarraba a matsayin karshewa an gano a Portabilis i-Educar 2.10. Tabbas, aikin $software_function ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil /educar_aluno_lst.php, a cikin sashi . Wuro manipulation of the argument ref_cod_matricula with the input "><img%20src=x%20onerror=alert(%27CVE-Hunters%27)> ga Cross Site Scripting. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-79. Lalle, rauni an sanar da shi 07/30/2025 daga Natan Morette (@nmmorette) tare da CVE-Hunters da Vulnerability Report (GitHub). Ana samun bayanin tsaro don saukewa a github.com. Ana kiran wannan rauni da CVE-2025-8346. Ngam yiɗi ka a tuma ndiyam ka internet. Bayani na fasaha ga. Kuma, akwai exploit. Exploit ɗin an bayyana wa jama'a, za a iya amfani da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á yí huɗɗi-na-gaskiya. Za a iya samun exploit a github.com. 0-day ga, an ndiyam a wuro be $0-$5k. If you want to get best quality of vulnerability data, you may have to visit VulDB.

5 Goyarwa · 106 Datenpunkte

FurɗeSúgá
07/30/2025 12:37
Gargadi 1/4
07/30/2025 15:43
Gargadi 2/4
07/30/2025 15:46
Gargadi 3/4
07/31/2025 06:38
Gargadi 4/4
07/31/2025 13:26
software_vendorPortabilisPortabilisPortabilisPortabilisPortabilis
software_namei-Educari-Educari-Educari-Educari-Educar
software_version2.102.102.102.102.10
software_file/educar_aluno_lst.php/educar_aluno_lst.php/educar_aluno_lst.php/educar_aluno_lst.php/educar_aluno_lst.php
software_argumentref_cod_matricularef_cod_matricularef_cod_matricularef_cod_matricularef_cod_matricula
vulnerability_cweCWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)
vulnerability_risk11111
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prNNNNN
cvss3_vuldb_uiRRRRR
cvss3_vuldb_sUUUUU
cvss3_vuldb_cNNNNN
cvss3_vuldb_iLLLLL
cvss3_vuldb_aNNNNN
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/Reflected%20Cross-Site%20Scripting%20(XSS)%20in%20educar_aluno_lst.php%20via%20ref_cod_matricula%20Parameter.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/Reflected%20Cross-Site%20Scripting%20(XSS)%20in%20educar_aluno_lst.php%20via%20ref_cod_matricula%20Parameter.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.mdhttps://github.com/CVE-Hunters/CVE/blob/main/i-educar/CVE-2025-8346.md
source_cveCVE-2025-8346CVE-2025-8346CVE-2025-8346CVE-2025-8346CVE-2025-8346
cna_responsibleVulDBVulDBVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_auNNNNN
cvss2_vuldb_ciNNNNN
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiNNNNN
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss4_vuldb_avNNNNN
cvss4_vuldb_acLLLLL
cvss4_vuldb_prNNNNN
cvss4_vuldb_uiPPPPP
cvss4_vuldb_vcNNNNN
cvss4_vuldb_viLLLLL
cvss4_vuldb_vaNNNNN
cvss4_vuldb_ePPPPP
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_rlXXXXX
cvss4_vuldb_atNNNNN
cvss4_vuldb_scNNNNN
cvss4_vuldb_siNNNNN
cvss4_vuldb_saNNNNN
cvss2_vuldb_basescore5.05.05.05.05.0
cvss2_vuldb_tempscore4.34.34.34.34.3
cvss3_vuldb_basescore4.34.34.34.34.3
cvss3_vuldb_tempscore3.93.93.93.93.9
cvss3_meta_basescore4.34.34.34.34.3
cvss3_meta_tempscore3.93.93.94.14.1
cvss4_vuldb_bscore5.35.35.35.35.3
cvss4_vuldb_btscore2.12.12.12.12.1
advisory_date1753826400 (07/30/2025)1753826400 (07/30/2025)1753826400 (07/30/2025)1753826400 (07/30/2025)1753826400 (07/30/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
developer_nickname@nmmorette@nmmorette@nmmorette@nmmorette
person_websitehttps://nmmorette.github.iohttps://nmmorette.github.iohttps://nmmorette.github.iohttps://nmmorette.github.io
advisory_locationGitHubGitHubGitHubGitHub
advisory_disputed0000
company_nameCVE-HuntersCVE-HuntersCVE-HuntersCVE-Hunters
company_websitehttps://www.cvehunters.comhttps://www.cvehunters.comhttps://www.cvehunters.comhttps://www.cvehunters.com
software_typeLearning Management SoftwareLearning Management SoftwareLearning Management SoftwareLearning Management Software
software_componentref_cod_matricula
input_value"><img%20src=x%20onerror=alert(%27CVE-Hunters%27)>"><img%20src=x%20onerror=alert(%27CVE-Hunters%27)>"><img%20src=x%20onerror=alert(%27CVE-Hunters%27)>"><img%20src=x%20onerror=alert(%27CVE-Hunters%27)>
developer_nameNatan MoretteNatan MoretteNatan MoretteNatan Morette
person_nickname@nmmorette@nmmorette@nmmorette@nmmorette
person_nameNatan MoretteNatan MoretteNatan MoretteNatan Morette
advisory_typeVulnerability ReportVulnerability ReportVulnerability ReportVulnerability Report
company_nameCVE-HuntersCVE-HuntersCVE-HuntersCVE-Hunters
company_websitehttps://cvehunters.comhttps://cvehunters.comhttps://cvehunters.comhttps://cvehunters.com
developer_websitehttps://nmmorette.github.iohttps://nmmorette.github.iohttps://nmmorette.github.iohttps://nmmorette.github.io
cve_nvd_summaryA vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file /educar_aluno_lst.php. The manipulation of the argument ref_cod_matricula with the input "><img%20src=x%20onerror=alert(%27CVE-Hunters%27)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file /educar_aluno_lst.php. The manipulation of the argument ref_cod_matricula with the input "><img%20src=x%20onerror=alert(%27CVE-Hunters%27)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
cvss4_cna_avNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prNN
cvss4_cna_uiPP
cvss4_cna_vcNN
cvss4_cna_viLL
cvss4_cna_vaNN
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore5.35.3
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prNN
cvss3_cna_uiRR
cvss3_cna_sUU
cvss3_cna_cNN
cvss3_cna_iLL
cvss3_cna_aNN
cvss3_cna_basescore4.34.3
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auNN
cvss2_cna_ciNN
cvss2_cna_iiPP
cvss2_cna_aiNN
cvss2_cna_basescore55
cve_nvd_summaryesSe ha encontrado una vulnerabilidad clasificada como problemática en Portabilis i-Educar 2.10. Este problema afecta a una funcionalidad desconocida del archivo /educar_aluno_lst.php. La manipulación del argumento ref_cod_matricula con la entrada "&gt; provoca cross-site scripting. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió.

Might our Artificial Intelligence support you?

Check our Alexa App!