CVE-2026-2064
- EPSS 0.03%
- Veröffentlicht 06.02.2026 19:32:07
- Zuletzt bearbeitet 11.02.2026 18:59:58
A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such manipulation of the argument File leads to cross si...
CVE-2026-2015
- EPSS 0.04%
- Veröffentlicht 06.02.2026 10:32:07
- Zuletzt bearbeitet 10.02.2026 18:15:12
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper a...
CVE-2025-9638
- EPSS 0.05%
- Veröffentlicht 09.12.2025 16:18:39
- Zuletzt bearbeitet 11.12.2025 17:56:54
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educar allows Stored Cross-Site Scripting (XSS) via the matricula_interna parameter in the educar_usuario_cad.php endpoint. This issue ...
CVE-2025-65022
- EPSS 0.04%
- Veröffentlicht 19.11.2025 16:02:13
- Zuletzt bearbeitet 20.11.2025 17:24:07
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access to an authenticated session can...
CVE-2025-65023
- EPSS 0.04%
- Veröffentlicht 19.11.2025 16:02:10
- Zuletzt bearbeitet 20.11.2025 17:20:18
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenti...
CVE-2025-65024
- EPSS 0.04%
- Veröffentlicht 19.11.2025 16:02:06
- Zuletzt bearbeitet 20.11.2025 17:11:17
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker with access to an authenticated s...
CVE-2025-11554
- EPSS 0.07%
- Veröffentlicht 09.10.2025 20:02:06
- Zuletzt bearbeitet 21.11.2025 15:07:46
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads...
CVE-2025-11050
- EPSS 0.03%
- Veröffentlicht 27.09.2025 05:15:30
- Zuletzt bearbeitet 03.10.2025 18:28:30
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been published and ...
CVE-2025-11049
- EPSS 0.03%
- Veröffentlicht 27.09.2025 04:15:50
- Zuletzt bearbeitet 03.10.2025 18:31:06
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. Performing manipulation results in improper authorization. Remote exploitation of the attack is possib...
CVE-2025-11048
- EPSS 0.03%
- Veröffentlicht 26.09.2025 22:15:33
- Zuletzt bearbeitet 07.10.2025 18:30:59
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched re...