CVE-2025-10584

Published
View on NVD ↗
CVSS v3
3.5
LOW
CVSS v2
4
MEDIUM
Affected
1
PROJECT

Description

A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVEs, PoCs, Payloads, CTFs and Bug Bounty
GitHubGitHub