CVE-2025-10590: Cross Site Scripting in Portabilis i-Educar
A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
CVE-2025-10590: Cross Site Scripting in Portabilis i-Educar
Description
A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-09-17T05:44:33.437Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68ca96e193b16c2d2a62e6cd
Added to database: 9/17/2025, 11:09:21 AM
Last updated: 9/17/2025, 11:09:21 AM
Views: 1
Related Threats
CVE-2025-10591: Cross Site Scripting in Portabilis i-Educar
MediumCVE-2025-10156: CWE-755: Improper Handling of Exceptional Conditions in mmaitre314 picklescan
CriticalCVE-2025-9972: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Planet Technology ICG-2510WG-LTE (EU/US)
CriticalCVE-2025-10155: CWE-20 Improper Input Validation in mmaitre314 picklescan
CriticalCVE-2025-0420: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Paraşüt Software Paraşüt
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.