No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21993 | A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of the argument filter[by_description] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of the argument filter[by_description] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A security flaw has been discovered in Portabilis i-Diario 1.5.0. The impacted element is an unknown function of the file /conteudos. Performing a manipulation of the argument filter[by_description] results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The patch is named d076c112b45e3b3e41cbe11de27949b491d922c2. It is recommended to apply a patch to fix this issue. The vendor confirms: "The searched term is now rendered escaped in the autocomplete widget, and the content tags are rendered through output-escaped templates, so an injected payload is displayed as inert text instead of being executed." |
| CPEs | cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:* | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Thu, 04 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portabilis
Portabilis i-diario |
|
| CPEs | cpe:2.3:a:portabilis:i-diario:1.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Portabilis
Portabilis i-diario |
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Jul 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of the argument filter[by_description] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Portabilis i-Diario conteudos cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-09T16:41:20.873Z
Reserved: 2025-07-19T05:52:59.414Z
Link: CVE-2025-7871
Updated: 2025-07-22T13:51:59.763Z
Status : Modified
Published: 2025-07-20T06:15:28.093
Modified: 2026-10-09T17:16:42.720
Link: CVE-2025-7871
No data.
OpenCVE Enrichment
No data.
EUVD