CNNVD-202512-1260 Information

CNNVD ID

CNNVD-202512-1260

CVE-2025-9638

  • CNNVD Published: 2025-12-09

Description (Chinese)

i-Educar是Portábilis开源的一个免费教育软件。 i-Educar 2.10.0版本存在安全漏洞,该漏洞源于educar_usuario_cad.php端点中matricula_interna参数输入中和不当,可能导致存储型跨站脚本攻击。

Description (English)

i-Educar is a free education software from Portábilis. i-Educar version 2.10.0 contains a security loophole, which originates from the inappropriate input of the matricula internationala parameter at the educar usuario cad.php endpoint, which may result in a storage-type cross-site script attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Portábilis

Published

2025-12-09

Last Modified

2026-02-24

References

https://fluidattacks.com/advisories/travis https://github.com/portabilis/i-educar

Share on: