CVE-2025-8544: Portabilis i-Educar edit cross site scripting
A vulnerability classified as problematic was found in Portabilis i-Educar 2.10. Affected by this vulnerability is an unknown functionality of the file /module/RegraAvaliacao/edit. The manipulation of the argument nome leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8544?
CVE-2025-8544 is classified as a problematic vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2025-8544?
To fix CVE-2025-8544, ensure that the application properly sanitizes and validates input in the affected file /module/RegraAvaliacao/edit.
What software is affected by CVE-2025-8544?
CVE-2025-8544 affects the Portabilis i-Educar version 2.10.
What type of attack can be executed using CVE-2025-8544?
CVE-2025-8544 allows attackers to execute cross-site scripting (XSS) attacks remotely.
Is user data at risk with CVE-2025-8544?
Yes, user data could be at risk due to the potential for cross-site scripting exploitation in CVE-2025-8544.