A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.
References
Configurations
History
03 Jul 2025, 00:29
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:portabilis:i-educar:2.9:*:*:*:*:*:*:* | |
References | () https://github.com/RegularUs3r/CVE-Research/blob/main/CVE-2024/Portabilis%20-%20iEducar/CVE-2024-55239%20-%20Reflected%20Cross-Site%20Scripting.md - Exploit, Third Party Advisory | |
References | () https://github.com/RegularUs3r/CVE-Research/blob/main/CVE-2024/Portabilis%20-%20iEducar/CVE-2024-55649%20-%20Reflected%20Cross-Site%20Scripting.md - Not Applicable | |
First Time |
Portabilis
Portabilis i-educar |
25 Dec 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-18 23:15
Updated : 2025-07-03 00:29
NVD link : CVE-2024-55239
Mitre link : CVE-2024-55239
CVE.ORG link : CVE-2024-55239
JSON object : View
Products Affected
portabilis
- i-educar
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')