Portabilis i-Educar ruo mgbe 2.10 educar_tipo_ensino_cad.php nm_tipo Nsụgharị koodu gafee weebụsaịtị

CVSS Ntughari oge metaỌnụ ahịa exploit ugbu a (≈)Mkpụrụ obi mmasị CTI
4.0$0-$5k0.12

Nchịkọtaozi

Achọpụtara adịghị ike a kpọrọ Isoro na Portabilis i-Educar ruo mgbe 2.10. Nke a metụtara ọrụ amaghi ama nke faịlụ /intranet/educar_tipo_ensino_cad.php. Nhazi a na arịrịọ nm_tipo na-eme ka Nsụgharị koodu gafee weebụsaịtị. Nke a bụ adịghị ike a na-akpọ CVE-2025-9738. E nwere ike ime ka mwakpo ahụ malite site n'ebe dị anya. N'ịbụ nke ọzọ, exploit dị. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Nkọwaozi

Achọpụtara adịghị ike a kpọrọ Isoro na Portabilis i-Educar ruo mgbe 2.10. Nke a metụtara ọrụ amaghi ama nke faịlụ /intranet/educar_tipo_ensino_cad.php. Nhazi a na arịrịọ nm_tipo na-eme ka Nsụgharị koodu gafee weebụsaịtị. Nsogbu a e kwuru site na CWE dị ka CWE-79. A kọrọ na enyo enyo a e bipụtara site n'aka Karina Gante (@KarinaGante) na CVE-Hunters. A kọọrọ ndụmọdụ ka e nwee ike ibudata ya na karinagante.github.io.

Nke a bụ adịghị ike a na-akpọ CVE-2025-9738. E nwere ike ime ka mwakpo ahụ malite site n'ebe dị anya. A na-enweta nkọwa teknụzụ. Ịkpoputa nke adịghị ike a dị n'okpuru nkezi. N'ịbụ nke ọzọ, exploit dị. A kpọrọ exploit ahụ n'ìhè ọha na eze ma nwee ike iji ya. Ugbu a, ọnụahịa dị ugbu a maka exploit might be approx. USD $0-$5k n'oge a. Dị ka ọrụ MITRE ATT&CK si kwuo, usoro mwakpo bụ T1059.007.

A na-akpọ ya Ẹ̀rí Èrò. A na-ekekọrịta exploit maka nbudata na karinagante.github.io.

If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Ọjaozi

Olupin

Orukọ

Àtúnse

CPE 2.3ozi

CPE 2.2ozi

CVSSv4ozi

VulDB Vekto: 🔒
VulDB Igbekele: 🔍

CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Vekto: 🔒

CVSSv3ozi

VulDB Ntughari isi nke meta: 4.1
VulDB Ntughari oge meta: 4.0

VulDB Isi nke isi: 3.5
VulDB Ntughari oge: 3.2
VulDB Vekto: 🔒
VulDB Igbekele: 🔍

NVD Isi nke isi: 5.4
NVD Vekto: 🔒

CNA Isi nke isi: 3.5
CNA Vekto: 🔒

CVSSv2ozi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
vekitọỊsòroÌmúdájúasiriìfaradàNnweta
ṣíṣíṣíṣíṣíṣí
ṣíṣíṣíṣíṣíṣí
ṣíṣíṣíṣíṣíṣí

VulDB Isi nke isi: 🔒
VulDB Ntughari oge: 🔒
VulDB Igbekele: 🔍

Ịjiozi

Klass: Nsụgharị koodu gafee weebụsaịtị
CWE: CWE-79 / CWE-94 / CWE-74
CAPEC: 🔒
ATT&CK: 🔒

arabara: Rara
Ime ụlọ: Rara
Nsọtụ: Bẹẹni

Nnweta: 🔒
Mbanye: Ọha
Ipo: Ẹ̀rí Èrò
Onkọwe: Karina Gante (@KarinaGante)
Gba: 🔒
Google Hack: 🔒

EPSS Score: 🔒
EPSS Percentile: 🔒

Ntụle ọnụahịa: 🔍
Ntụle ọnụahịa ugbu a: 🔒

0-Dayṣíṣíṣíṣí
Taaṣíṣíṣíṣí

Ìmọ̀ nípa ìkìlọ̀ozi

Mmasị: 🔍
Ndị na-eme ihe nkiri na-arụsi ọrụ ike: 🔍
Ọgbakọ APT na-arụsi ọrụ ike: 🔍

igbaradiozi

àbá: enweghị enyemaka a maara
Ipo: 🔍

ọjọ́ 0: 🔒

ahịrị ogeozi

30/08/2025 Imọran ti jade
30/08/2025 +0 ụbọchị Ìforúkọ VulDB ti ṣẹda
22/09/2025 +23 ụbọchị Ìmúdájú ìkẹyìn VulDB

Orísunozi

Imọran: karinagante.github.io
Olùwádìí: Karina Gante (@KarinaGante)
Ẹgbẹ́: CVE-Hunters
Ipo: A kò ṣàlàyé

CVE: CVE-2025-9738 (🔒)
GCVE (CVE): GCVE-0-2025-9738
GCVE (VulDB): GCVE-100-322037
EUVD: 🔒
scip Labs: https://www.scip.ch/en/?labs.20161013

nbanyeozi

E kere: 30/08/2025 06:47 PM
Emelitere: 22/09/2025 09:32 PM
Mgbanwe: 30/08/2025 06:47 PM (56), 31/08/2025 07:51 PM (30), 31/08/2025 09:54 PM (1), 05/09/2025 12:12 AM (11), 22/09/2025 09:31 PM (3), 22/09/2025 09:32 PM (8)
Zukuru: 🔍
Olùránṣẹ́: karinagante
Olùṣe ìpinnu: karinagante
Cache ID: 253:D66:103

fi silẹozi

Anabata

  • fi silẹ #638703: Portabilis i-Educar 2.10 Cross Site Scripting (nípasẹ̀ karinagante)

Mkparịta ụka

Enweghị okwu nke ọ bụla Asụsụ: ig + en.

Biko banye ka ikwu okwu

Do you need the next level of professionalism?

Upgrade your account now!