CVE-2025-9724

LOW

Portabilis i-Educar <2.10 - XSS

Title source: llm

Description

A vulnerability was determined in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /intranet/educar_nivel_ensino_cad.php. Executing manipulation of the argument nm_nivel/descricao can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Exploits (1)

github WRITEUP
by KarinaGante · htmlpoc
https://github.com/KarinaGante/KG-Sec/tree/main/CVEs/i-Educar/CVE-2025-9724.md

Scores

CVSS v3 3.5
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-94 CWE-79
Status published

Affected Products (1)

portabilis/i-educar < 2.10

Timeline

Published Aug 31, 2025
Tracked Since Feb 18, 2026