CVE-2025-9652
LOWPortabilis i-Educar < 2.10 - Cross-Site Scripting via nm_tipo/desc_tipo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-9652. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains detailed writeups for multiple CVEs, including CVE-2025-10909, which describes a stored XSS vulnerability via SVG file upload bypass in NovoSGA. The analysis includes technical details, PoC payloads, and impact assessments.
Description
A vulnerability was determined in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /intranet/educar_transferencia_tipo_cad.php of the component Cadastrar tipo de transferência Page. This manipulation of the argument nm_tipo/desc_tipo causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Exploits (1)
The repository contains detailed writeups for multiple CVEs, including CVE-2025-10909, which describes a stored XSS vulnerability via SVG file upload bypass in NovoSGA. The analysis includes technical details, PoC payloads, and impact assessments.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N