CVE-2023-5578

Executive Summary

CVE‑2023‑5578 is a reflected XSS flaw in Portábilis i‑Educar ≤2.7.5 via the cod_agenda parameter in intranet/agenda_imprimir.php. Malicious input such as ");'> triggers script execution in the victim’s browser, enabling remote attackers to steal session cookies or perform other client‑side attacks. The vulnerable endpoint has been removed in newer releases, so the issue is mitigated by upgrading. The vulnerability is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 3.5 (LOW) - Published: 2023-10-14T11:15:45.800 - Last Modified: 2026-09-15T03:17:03.637

Original Description: A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: "This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed."

"Limitations live only in our minds. But if we use our imaginations, our possibilities become limitless."

— Jamie Paolinetti
Source: NVD