CVE-2025-7113: Portabilis i-Educar Curricular Components Module edit cross site scripting
A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/ComponenteCurricular/edit?id=ID of the component Curricular Components Module. The manipulation of the argument Nome leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7113?
CVE-2025-7113 has been classified as problematic.
How do I fix CVE-2025-7113?
To fix CVE-2025-7113, update Portabilis i-Educar to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-7113?
CVE-2025-7113 is a cross-site scripting (XSS) vulnerability.
Which component of Portabilis i-Educar is affected by CVE-2025-7113?
CVE-2025-7113 affects the Curricular Components Module in Portabilis i-Educar.
What is the impact of CVE-2025-7113?
The impact of CVE-2025-7113 can lead to unauthorized access and manipulation of user data.