CVE-2025-8539: Portabilis i-Educar public_distrito_cad.php cross site scripting
A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/publicdistritocad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.12 mitigates this issue. It is recommended to upgrade the affected component. The vendor explains, that "[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Portabilis i-Educarto a version that resolves this vulnerability.Fixed in 2.12
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8539?
CVE-2025-8539 is classified as a problematic vulnerability affecting Portabilis i-Educar.
What type of vulnerability is CVE-2025-8539?
CVE-2025-8539 is a cross-site scripting (XSS) vulnerability.
What affected functionality does CVE-2025-8539 target?
CVE-2025-8539 impacts the functionality of the file /intranet/public_distrito_cad.php in Portabilis i-Educar.
How can I fix CVE-2025-8539?
To fix CVE-2025-8539, ensure input sanitization is implemented for the 'nome' argument in the affected file.
Can CVE-2025-8539 be exploited remotely?
Yes, CVE-2025-8539 can be exploited remotely by manipulating the 'nome' parameter.