CVE-2025-8538

Executive Summary

CVE-2025-8538: Cross‑site scripting in Portabilis i‑Educar 2.10 via the /usuarios/tipos/novo endpoint. Malicious input in the name/description fields triggers XSS, enabling remote attackers to inject arbitrary scripts. Public exploit available; can be used for defacement, cookie theft, or session hijacking. Upgrade to 2.12 or later to mitigate. Not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 2.4 (LOW) - Published: 2025-08-05T01:15:43.567 - Last Modified: 2026-09-15T03:17:05.000

Original Description: A security flaw has been discovered in Portabilis i-Educar 2.10. The impacted element is an unknown function of the file /usuarios/tipos/novo. The manipulation of the argument name/description results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.12 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor explains, that "[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced".

"I believe that every person is born with talent."

— Maya Angelou
Source: NVD