CVE-2025-8543: Portabilis i-Educar educar_raca_cad.php cross site scripting
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. Affected is an unknown function of the file /intranet/educarracacad.php. The manipulation of the argument nmraca leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8543?
The severity of CVE-2025-8543 is classified as problematic due to its potential for exploitation through cross-site scripting.
How does CVE-2025-8543 affect Portabilis i-Educar?
CVE-2025-8543 affects Portabilis i-Educar by allowing remote attackers to manipulate the nm_raca argument, leading to cross-site scripting vulnerabilities.
How can I fix CVE-2025-8543?
To fix CVE-2025-8543, validate and sanitize the input parameters in the /intranet/educar_raca_cad.php file to prevent cross-site scripting.
Is CVE-2025-8543 a remote exploitation vulnerability?
Yes, CVE-2025-8543 allows remote exploitation through cross-site scripting, making it a serious security concern.
What versions of Portabilis i-Educar are affected by CVE-2025-8543?
CVE-2025-8543 has been identified in Portabilis i-Educar version 2.10.