A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 04 Sep 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Portabilis
Portabilis i-diario
CPEs cpe:2.3:a:portabilis:i-diario:1.5.0:*:*:*:*:*:*:*
Vendors & Products Portabilis
Portabilis i-diario

Tue, 22 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Jul 2025 05:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Portabilis i-Diario justificativas-de-falta Endpoint cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-07-20T05:32:06.300Z

Updated: 2025-07-22T13:56:38.818Z

Reserved: 2025-07-19T05:52:56.313Z

Link: CVE-2025-7870

cve-icon Vulnrichment

Updated: 2025-07-22T13:56:29.831Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-20T06:15:26.920

Modified: 2025-09-04T15:39:34.193

Link: CVE-2025-7870

cve-icon Redhat

No data.