A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> <script>alert(document.cookie)</script> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: "This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed."
References
| Link | Resource |
|---|---|
| https://github.com/portabilis/i-educar | |
| https://vuldb.com/cve/CVE-2023-5578 | |
| https://vuldb.com/submit/217053 | |
| https://vuldb.com/submit/649873 | |
| https://vuldb.com/vuln/242143 | |
| https://vuldb.com/vuln/242143/cti | |
| https://vuldb.com/?ctiid.242143 | Permissions Required VDB Entry |
| https://vuldb.com/?id.242143 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2023-10-14 11:15
Updated : 2026-09-15 03:17
NVD link : CVE-2023-5578
Mitre link : CVE-2023-5578
CVE.ORG link : CVE-2023-5578
JSON object : View
Products Affected
portabilis
- i-educar
