CVE-2025-10606: Cross Site Scripting in Portabilis i-Educar
A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
CVE-2025-10606: Cross Site Scripting in Portabilis i-Educar
Description
A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-09-17T07:04:43.965Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68caf94c33b75e972181a54e
Added to database: 9/17/2025, 6:09:16 PM
Last updated: 9/17/2025, 6:09:16 PM
Views: 1
Related Threats
CVE-2025-59342: CWE-24: Path Traversal: '../filedir' in esm-dev esm.sh
MediumCVE-2025-10607: Information Disclosure in Portabilis i-Educar
MediumCVE-2025-59341: CWE-23: Relative Path Traversal in esm-dev esm.sh
HighCVE-2025-10597: SQL Injection in kidaze CourseSelectionSystem
MediumCVE-2025-58767: CWE-400: Uncontrolled Resource Consumption in ruby rexml
LowActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.