CVE-2025-10584
LOWPortabilis i-Educar < 2.10.0 - Cross-Site Scripting via nm_anotacao/descricao Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-10584. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains a detailed writeup for CVE-2025-10584, focusing on a directory traversal vulnerability in i-Educar. It includes technical details, proof-of-concept steps, and screenshots demonstrating the exploit.
Description
A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Exploits (1)
The repository contains a detailed writeup for CVE-2025-10584, focusing on a directory traversal vulnerability in i-Educar. It includes technical details, proof-of-concept steps, and screenshots demonstrating the exploit.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N