A vulnerability was detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/TabelaArredondamento/edit of the component Cadastrar tabela de arredondamento Page. The manipulation of the argument Nome results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used.
References
| Link | Resource |
|---|---|
| https://karinagante.github.io/cve-2025-9720/ | |
| https://karinagante.github.io/cve-2025-9720/#poc | |
| https://vuldb.com/?ctiid.322009 | Permissions Required VDB Entry |
| https://vuldb.com/?id.322009 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.638671 | Third Party Advisory VDB Entry |
Configurations
History
13 Oct 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A vulnerability was detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/TabelaArredondamento/edit of the component Cadastrar tabela de arredondamento Page. The manipulation of the argument Nome results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. | |
| References |
|
|
03 Sep 2025, 16:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/15.md - Broken Link | |
| References | () https://vuldb.com/?ctiid.322009 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.322009 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.638671 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* | |
| First Time |
Portabilis
Portabilis i-educar |
31 Aug 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-31 07:15
Updated : 2025-10-13 21:15
NVD link : CVE-2025-9720
Mitre link : CVE-2025-9720
CVE.ORG link : CVE-2025-9720
JSON object : View
Products Affected
portabilis
- i-educar
