Portabilis i-Educar har 2.10 educar_tipo_ensino_cad.php nm_tipo Cross Site Scripting

Hakika vulnerability da aka rarraba a matsayin karshewa an gano a Portabilis i-Educar har 2.10. Tabbas, aikin $software_function ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil /intranet/educar_tipo_ensino_cad.php, a cikin sashi $software_component. Wuro manipulation of the argument nm_tipo ga Cross Site Scripting. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-79. Lalle, rauni an sanar da shi 08/30/2025 daga Karina Gante (@KarinaGante) tare da CVE-Hunters. Ana samun bayanin tsaro don saukewa a karinagante.github.io. Ana kiran wannan rauni da CVE-2025-9738. Ngam yiɗi ka a tuma ndiyam ka nder internet. Bayani na fasaha ga. Kuma, akwai exploit. Exploit ɗin an bayyana wa jama'a, za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á yí huɗɗi-na-gaskiya. Za a iya samun exploit a karinagante.github.io. 0-day ga, an ndiyam a wuro be $0-$5k. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

6 Goyarwa · 109 Datenpunkte

FurɗeGargadi 1/5
08/31/2025 19:51
Gargadi 2/5
08/31/2025 21:54
Gargadi 3/5
09/05/2025 00:12
Gargadi 4/5
09/22/2025 21:31
Gargadi 5/5
09/22/2025 21:32
software_vendorPortabilisPortabilisPortabilisPortabilisPortabilis
software_namei-Educari-Educari-Educari-Educari-Educar
software_version<=2.10<=2.10<=2.10<=2.10<=2.10
software_file/intranet/educar_tipo_ensino_cad.php/intranet/educar_tipo_ensino_cad.php/intranet/educar_tipo_ensino_cad.php/intranet/educar_tipo_ensino_cad.php/intranet/educar_tipo_ensino_cad.php
software_argumentnm_tiponm_tiponm_tiponm_tiponm_tipo
vulnerability_cweCWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)
vulnerability_risk11111
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prLLLLL
cvss3_vuldb_uiRRRRR
cvss3_vuldb_sUUUUU
cvss3_vuldb_cNNNNN
cvss3_vuldb_iLLLLL
cvss3_vuldb_aNNNNN
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.mdhttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.mdhttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.mdhttps://karinagante.github.io/cve-2025-9738/https://karinagante.github.io/cve-2025-9738/
person_nameKarina GanteKarina GanteKarina GanteKarina GanteKarina Gante
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.md#pochttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.md#pochttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.md#pochttps://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/20.md#pochttps://karinagante.github.io/cve-2025-9738/#proof-of-concept-poc
source_cveCVE-2025-9738CVE-2025-9738CVE-2025-9738CVE-2025-9738CVE-2025-9738
cna_responsibleVulDBVulDBVulDBVulDBVulDB
cvss2_vuldb_tempscore3.43.43.43.43.4
cvss3_vuldb_basescore3.53.53.53.53.5
cvss3_vuldb_tempscore3.23.23.23.23.2
cvss3_meta_basescore3.53.54.14.14.1
cvss3_meta_tempscore3.33.34.04.04.0
cvss4_vuldb_bscore5.15.15.15.15.1
cvss4_vuldb_btscore2.02.02.02.02.0
advisory_date1756504800 (08/30/2025)1756504800 (08/30/2025)1756504800 (08/30/2025)1756504800 (08/30/2025)1756504800 (08/30/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciNNNNN
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiNNNNN
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss4_vuldb_avNNNNN
cvss4_vuldb_acLLLLL
cvss4_vuldb_prLLLLL
cvss4_vuldb_uiPPPPP
cvss4_vuldb_vcNNNNN
cvss4_vuldb_viLLLLL
cvss4_vuldb_vaNNNNN
cvss4_vuldb_ePPPPP
cvss2_vuldb_auSSSSS
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_rlXXXXX
cvss4_vuldb_atNNNNN
cvss4_vuldb_scNNNNN
cvss4_vuldb_siNNNNN
cvss4_vuldb_saNNNNN
cvss2_vuldb_basescore4.04.04.04.04.0
cve_nvd_summaryA flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
cvss4_cna_avNNNNN
cvss4_cna_acLLLLL
cvss4_cna_atNNNNN
cvss4_cna_prLLLLL
cvss4_cna_uiPPPPP
cvss4_cna_vcNNNNN
cvss4_cna_viLLLLL
cvss4_cna_vaNNNNN
cvss4_cna_scNNNNN
cvss4_cna_siNNNNN
cvss4_cna_saNNNNN
cvss4_cna_bscore5.15.15.15.15.1
cvss3_cna_avNNNNN
cvss3_cna_acLLLLL
cvss3_cna_prLLLLL
cvss3_cna_uiRRRRR
cvss3_cna_sUUUUU
cvss3_cna_cNNNNN
cvss3_cna_iLLLLL
cvss3_cna_aNNNNN
cvss3_cna_basescore3.53.53.53.53.5
cvss2_cna_avNNNNN
cvss2_cna_acLLLLL
cvss2_cna_auSSSSS
cvss2_cna_ciNNNNN
cvss2_cna_iiPPPPP
cvss2_cna_aiNNNNN
cvss2_cna_basescore44444
euvd_idEUVD-2025-26302EUVD-2025-26302EUVD-2025-26302EUVD-2025-26302
cvss3_nvd_avNNN
cvss3_nvd_acLLL
cvss3_nvd_prLLL
cvss3_nvd_uiRRR
cvss3_nvd_sCCC
cvss3_nvd_cLLL
cvss3_nvd_iLLL
cvss3_nvd_aNNN
cvss3_nvd_basescore5.45.45.4
developer_nickname@KarinaGante@KarinaGante
developer_nameKarina GanteKarina Gante
person_websitehttps://karinagante.github.io
company_nameCVE-Hunters
person_nickname@KarinaGante
company_nameCVE-Hunters
company_websitehttps://www.cvehunters.com/
company_websitehttps://www.cvehunters.com/
developer_websitehttps://karinagante.github.io

Want to stay up to date on a daily basis?

Enable the mail alert feature now!