Portabilis i-Educar public_distrito_cad.php cross site scripting
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.8epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/public_distrito_cad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.12 mitigates this issue. It is recommended to upgrade the affected component. The vendor explains, that "[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced".
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
Portabilis · i-EducarReferences
https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/CVE-2025-8539.mdhttps://github.com/portabilis/i-educar/tree/2.12https://karinagante.github.io/cve-2025-8539/https://vuldb.com/cve/CVE-2025-8539https://vuldb.com/?submit.620453https://vuldb.com/submit/620453https://vuldb.com/vuln/318668https://vuldb.com/vuln/318668/cti