CVE-2025-7113
- EPSS 0.03%
- Veröffentlicht 07.07.2025 05:15:42
- Zuletzt bearbeitet 13.08.2025 14:42:29
A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/ComponenteCurricular/edit?id=ID of the component Curricular Components Module. The manipulation of the ...
CVE-2025-7112
- EPSS 0.03%
- Veröffentlicht 07.07.2025 04:32:04
- Zuletzt bearbeitet 13.08.2025 14:42:38
A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intranet/educar_funcao_det.php?cod_funcao=COD&ref_cod_instituicao=COD of the component Function Management M...
CVE-2025-7111
- EPSS 0.03%
- Veröffentlicht 07.07.2025 04:02:07
- Zuletzt bearbeitet 13.08.2025 14:42:34
A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intranet/educar_curso_det.php?cod_curso=ID of the component Course Module. The manipulation of the argumen...
CVE-2025-7110
- EPSS 0.03%
- Veröffentlicht 07.07.2025 03:32:05
- Zuletzt bearbeitet 13.08.2025 14:42:42
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educar_escola_lst.php of the component School Module. The manipulation of the argument Escola leads to cr...
CVE-2025-7109
- EPSS 0.03%
- Veröffentlicht 07.07.2025 03:15:30
- Zuletzt bearbeitet 13.08.2025 14:42:45
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file /intranet/educar_aluno_beneficio_lst.php of the component Student Benefits Registratio...
CVE-2024-55651
- EPSS 0.14%
- Veröffentlicht 07.05.2025 23:49:46
- Zuletzt bearbeitet 17.06.2025 19:44:30
i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de U...
CVE-2024-12893
- EPSS 0.11%
- Veröffentlicht 22.12.2024 08:15:06
- Zuletzt bearbeitet 02.07.2025 19:09:29
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this issue is some unknown functionality of the file /usuarios/tipos/2 of the component Tipo de Usuário Page. The manipulation of the a...
CVE-2024-55239
- EPSS 0.07%
- Veröffentlicht 18.12.2024 23:15:17
- Zuletzt bearbeitet 03.07.2025 00:29:26
A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.
CVE-2024-48325
- EPSS 9.71%
- Veröffentlicht 06.11.2024 23:15:04
- Zuletzt bearbeitet 24.06.2025 16:31:44
Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituica...
CVE-2024-45059
- EPSS 0.14%
- Veröffentlicht 28.08.2024 21:15:07
- Zuletzt bearbeitet 13.09.2024 20:09:19
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_...