Marcelo Queiroz
23 exploits
Active since Jul 2025
Portabilis i-educar < 2.10.0 - SQL Injection via ref_cod_aluno Parameter
CVSS 6.3
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in /exportacao-para-o-seb Endpoint
CVSS 6.3
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in /enturmacao-em-lote/ Endpoint
CVSS 6.3
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in /cancelar-enturmacao-em-lote/ Endpoint
CVSS 6.3
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in /matricula/[ID_STUDENT]/enturmar/ Endpoint
CVSS 6.3
Portabilis i-educar < 2.10.0 - Broken Object Level Authorization via /module/Api/turma
CVSS 4.3
Portabilis i-educar < 2.10.0 - Cross-Site Scripting via educar_usuario_cad.php Email Parameter
CVSS 2.4
Portabilis i-educar < 2.10.0 - Cross-Site Scripting via tipoacao Parameter in agenda_preferencias.php
CVSS 4.3
Portabilis i-educar < 2.10.0 - Exposure of Sensitive Information via /module/Avaliacao/diarioApi
CVSS 4.3
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in Enrollment History Endpoint
CVSS 6.3
Portabilis i-Educar <2.10 - Info Disclosure
CVSS 6.3
Portabilis i-Educar <2.10 - Auth Bypass
CVSS 6.3
Portabilis i-Diario 1.5.0 - Cross-Site Scripting via Justificativa Parameter
CVSS 3.5
Portabilis i-Educar 2.9 - Cross-Site Scripting via campo_busca/cpf Parameters
CVSS 4.3
scada-lts < 2.7.8.1 - Stored Cross-Site Scripting in Virtual Data Source Property Handler via Name Parameter
CVSS 3.5
Portabilis i-Diario <= 1.5.0 - Stored Cross-Site Scripting in Registro das atividades
CVSS 3.5
Portabilis i-Diario < 1.5.0 - Stored Cross-Site Scripting via Parecer/Objeto de Conhecimento/Habilidades Parameters
CVSS 3.5
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3