CVE-2025-7867: Cross Site Scripting in Portabilis i-Educar
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9.0. Affected is an unknown function of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novo_titulo leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-7867: Cross Site Scripting in Portabilis i-Educar
Description
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9.0. Affected is an unknown function of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novo_titulo leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-19T05:52:47.739Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687c7115a83201eaac00e916
Added to database: 7/20/2025, 4:31:17 AM
Last updated: 7/20/2025, 4:31:17 AM
Views: 1
Related Threats
CVE-2025-7866: Cross Site Scripting in Portabilis i-Educar
MediumCVE-2025-7865: Cross Site Scripting in thinkgem JeeSite
MediumCVE-2025-7864: Unrestricted Upload in thinkgem JeeSite
MediumCVE-2025-7863: Open Redirect in thinkgem JeeSite
MediumCVE-2025-7862: Missing Authentication in TOTOLINK T6
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.