Portabilis i-Educar
cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*
- 2.9.0
A stored cross-site scripting vulnerability has been identified in Portabilis i-Educar version 2.9.0, specifically within the Turma module. The issue arises in the file 'intranet/educar_turma_tipo_det.php' when the 'cod_turma_tipo' parameter is used. The vulnerability is triggered by manipulating the 'nm_tipo' argument, allowing attackers to inject malicious JavaScript that is executed in the context of the user viewing the affected page. This vulnerability can be exploited remotely and requires user interaction.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, log into the i-Educar platform and navigate to the Turma module. Access the 'Tipo de Turma' section and either edit an existing 'Turma Tipo' or create a new one. Insert a script payload into the 'Turma Tipo' field and save the changes. When the page is reopened, the injected script will execute.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.