CVE-2025-10372
LOWPortabilis i-educar < 2.10.0 - Cross-Site Scripting via nm_tipo/descricao Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-10372. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains a detailed technical writeup for CVE-2025-10372, focusing on a directory traversal vulnerability in i-Educar. It includes step-by-step exploitation details, screenshots, and references, demonstrating a clear understanding of the vulnerability.
Description
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Exploits (1)
The repository contains a detailed technical writeup for CVE-2025-10372, focusing on a directory traversal vulnerability in i-Educar. It includes step-by-step exploitation details, screenshots, and references, demonstrating a clear understanding of the vulnerability.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N