CVE-2025-8368: Portabilis i-Educar pesquisa_pessoa_lst.php cross site scripting
A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code of the file /intranet/pesquisapessoalst.php. The manipulation of the argument campobusca/cpf leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8368?
CVE-2025-8368 is classified as a problematic vulnerability.
How do I fix CVE-2025-8368?
To fix CVE-2025-8368, you should implement input validation and sanitization for the campo_busca/cpf parameter.
What type of attack does CVE-2025-8368 allow?
CVE-2025-8368 allows for cross-site scripting (XSS) attacks.
Which software is affected by CVE-2025-8368?
The affected software for CVE-2025-8368 is Portabilis i-Educar version 2.9.
Can CVE-2025-8368 be exploited remotely?
Yes, CVE-2025-8368 can be exploited remotely.