No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21994 | A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability was identified in Portabilis i-Diario 1.5.0. The affected element is an unknown function of the file app/uploaders/doc_uploader.rb of the component justificativas-de-falta Endpoint. Such manipulation of the argument Anexo leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is 6c529bb2d96130aa29533f49e204e86518e11fdd. It is best practice to apply a patch to resolve this issue. The vendor confirms: "The attachment uploader now rejects files whose declared content type indicates executable or markup content". |
| Title | Portabilis i-Diario justificativas-de-falta Endpoint cross site scripting | Portabilis i-Diario justificativas-de-falta Endpoint doc_uploader.rb cross site scripting |
| CPEs | cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:* | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Thu, 04 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portabilis
Portabilis i-diario |
|
| CPEs | cpe:2.3:a:portabilis:i-diario:1.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Portabilis
Portabilis i-diario |
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Jul 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Portabilis i-Diario justificativas-de-falta Endpoint cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-09T16:38:36.888Z
Reserved: 2025-07-19T05:52:56.313Z
Link: CVE-2025-7870
Updated: 2025-07-22T13:56:29.831Z
Status : Modified
Published: 2025-07-20T06:15:26.920
Modified: 2026-10-09T17:16:42.343
Link: CVE-2025-7870
No data.
OpenCVE Enrichment
No data.
EUVD