A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.
References
Configurations
History
03 Jul 2025, 00:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/RegularUs3r/CVE-Research/blob/main/CVE-2024/Portabilis%20-%20iEducar/CVE-2024-55239%20-%20Reflected%20Cross-Site%20Scripting.md - Exploit, Third Party Advisory | |
References | () https://github.com/RegularUs3r/CVE-Research/blob/main/CVE-2024/Portabilis%20-%20iEducar/CVE-2024-55649%20-%20Reflected%20Cross-Site%20Scripting.md - Not Applicable | |
First Time |
Portabilis i-educar
Portabilis |
|
CPE | cpe:2.3:a:portabilis:i-educar:2.9:*:*:*:*:*:*:* |
25 Dec 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CWE | CWE-79 | |
References | () https://github.com/RegularUs3r/CVE-Research/blob/main/CVE-2024/Portabilis%20-%20iEducar/CVE-2024-55239%20-%20Reflected%20Cross-Site%20Scripting.md - |
24 Dec 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
18 Dec 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-18 23:15
Updated : 2025-07-03 00:29
NVD link : CVE-2024-55239
Mitre link : CVE-2024-55239
CVE.ORG link : CVE-2024-55239
JSON object : View
Products Affected
portabilis
- i-educar
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')