Portabilis i-Educar Cross-Site Scripting Vulnerability in educar_usuario_det.php

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Portabilis i-Educar versions through 2.10. The issue arises in the educar_usuario_det.php file, where the ref_pessoa parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely, requiring user interaction.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, log into the i-Educar application with an account that can create or edit users. Navigate to the 'educar_usuario_det.php' endpoint, typically found under 'Configurações > Permissões > Usuários'. Once there, modify the URL to include a payload that exploits the ref_pessoa parameter by injecting a script, such as a JavaScript alert. When the crafted URL is loaded, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Sep 17, 2025, 11:24 AM
Updated: Sep 17, 2025, 2:38 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.