CVE-2025-9722 | Portabilis i-Educar up to 2.10 educar_tipo_ocorrencia_disciplinar_cad.php nm_tipo/descricao cross site scripting (EUVD-2025-26288)
A vulnerability labeled as problematic has been found in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_tipo_ocorrencia_disciplinar_cad.php. Such manipulation of the argument nm_tipo/descricao leads to cross site scripting.
This vulnerability is referenced as CVE-2025-9722. It is possible to launch the attack remotely. Furthermore, an exploit is available.