CVE-2025-8365: Portabilis i-Educar atendidos_cad.php cross site scripting
A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file atendidoscad.php. The manipulation of the argument nome/nomesocial/email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8365?
CVE-2025-8365 has been declared as a problematic vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-8365?
To fix CVE-2025-8365, sanitize and validate all user inputs to the atendidos_cad.php file to prevent cross-site scripting.
What is affected by CVE-2025-8365?
CVE-2025-8365 affects the Portabilis i-Educar software, specifically the atendidos_cad.php functionality.
What type of vulnerability is CVE-2025-8365?
CVE-2025-8365 is categorized as a cross-site scripting (XSS) vulnerability.
How can I protect my application from CVE-2025-8365?
Implement input sanitization and output encoding throughout your application to mitigate the risks associated with CVE-2025-8365.