Portabilis i-Diario Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Portabilis i-Diario version 1.6. The issue arises in the 'Dicionário de Termos BNCC' page, specifically within the 'Planos de ensino' input field. The vulnerability allows users to inject arbitrary JavaScript, which is executed when the 'Planos de ensino por disciplina' or 'Planos de ensino por áreas do conhecimento' pages are accessed. This exploitation can be performed remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, navigate to the 'Dicionário de Termos BNCC' page and locate the 'Planos de ensino' input field. Insert a payload, such as an image tag with an 'onerror' event, into the field. Once the payload is saved, access the 'Planos de ensino por disciplina' or 'Planos de ensino por áreas do conhecimento' pages to trigger the injected script.

Added: Aug 13, 2025, 8:52 PM
Updated: Aug 13, 2025, 8:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.