CVE-2025-8367: Portabilis i-Educar funcionario_vinculo_lst.php cross site scripting
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the file /intranet/funcionariovinculolst.php. The manipulation of the argument nome leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8367?
CVE-2025-8367 is classified as a problematic vulnerability due to its potential for cross-site scripting attacks.
How does CVE-2025-8367 affect Portabilis i-Educar?
CVE-2025-8367 affects the /intranet/funcionario_vinculo_lst.php file by allowing manipulation of the 'nome' argument, which can lead to cross-site scripting.
Can CVE-2025-8367 be exploited remotely?
Yes, CVE-2025-8367 can be exploited remotely, which increases the risk of attacks.
What steps should be taken to mitigate CVE-2025-8367?
To mitigate CVE-2025-8367, it is essential to sanitize and validate input for the 'nome' argument in the affected PHP file.
Is there a patch available for CVE-2025-8367?
As of now, there is no official patch released for CVE-2025-8367, so users should implement immediate security measures.