CVE-2025-7867: Portabilis i-Educar Agenda agenda.php cross site scripting
A vulnerability has been found in Portabilis i-Educar 2.9.0/2.10.0. This vulnerability affects unknown code of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novotitulo/novodescricao leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7867?
CVE-2025-7867 is classified as problematic due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-7867?
To fix CVE-2025-7867, sanitize and validate user inputs in the novo_titulo parameter to prevent script execution.
What software is affected by CVE-2025-7867?
CVE-2025-7867 affects Portabilis i-Educar version 2.9.0.
What type of vulnerability is CVE-2025-7867?
CVE-2025-7867 is a cross-site scripting (XSS) vulnerability.
Can CVE-2025-7867 be exploited remotely?
Yes, CVE-2025-7867 can be exploited remotely if an attacker can manipulate the novo_titulo argument in the agenda.php file.