CVE-2025-9638
EUVD-2025-20228609.12.2025, 16:18
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educar allows Stored Cross-Site Scripting (XSS) via the matricula_interna parameter in the educar_usuario_cad.php endpoint.
This issue affects i-Educar: 2.10.0.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| portabilis | i-educar | 2.10.0 |
𝑥
= Vulnerable software versions