{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T06:36:40.785","vulnerabilities":[{"cve":{"id":"CVE-2024-45057","sourceIdentifier":"security-advisories@github.com","published":"2024-08-28T21:15:07.027","lastModified":"2024-09-13T20:03:10.947","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the dynamic generation of HTML fields prior to the 2.9 branch. The file located at `ieducar/intranet/include/clsCampos.inc.php` does not properly validate or sanitize user-controlled input, leading to the vulnerability. Any page that uses this implementation is vulnerable, such as `intranet/educar_curso_lst.php?nm_curso=<payload>`, `intranet/atendidos_lst.php?nm_pessoa=<payload>`, `intranet/educar_abandono_tipo_lst?nome=<payload>`. Commit f2d768534aabc09b2a1fc8a5cc5f9c93925cb273 contains a patch for the issue."},{"lang":"es","value":"i-Educar es un software de gestión escolar totalmente online y gratuito que permite a las secretarias, profesores, coordinadores y responsables de área de la escuela gestionar de forma dinámica los valores de los campos HTML. La falta de desinfección de los parámetros controlados por el usuario para generar dinámicamente los valores de los campos HTML conduce a ataques XSS (Cross-Site Scripting). La generación dinámica de los campos HTML en el archivo ieducar/intranet/include/clsCampos.inc.php no realiza la validación o desinfección correcta, reflejando los valores controlados por el usuario que se mostrarán en el HTML de la página. Esto permite a un atacante inyectar un payload XSS específico en un parámetro. La explotación exitosa de esta falla permite a un atacante engañar a la víctima para que haga clic en una URL vulnerable, lo que permite que se ejecuten scripts de JavaScript en el navegador. Debido a la configuración de las cookies de sesión, con los flags HttpOnly y SameSite=Lax definidos, es poco lo que un atacante puede hacer para robar la sesión o forzar a la víctima a realizar acciones dentro de la aplicación. Este problema ha sido parcheado pero aún no se ha realizado una nueva versión. Se recomienda a los usuarios que se pongan en contacto con el desarrollador y coordinen un cronograma de actualización."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV30":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:*","versionEndIncluding":"2.9","matchCriteriaId":"BAA7BA67-9C1B-461B-90CF-2BB79C838BAF"}]}]}],"references":[{"url":"https://github.com/portabilis/i-educar/commit/f2d768534aabc09b2a1fc8a5cc5f9c93925cb273","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/portabilis/i-educar/security/advisories/GHSA-fqwh-c3c8-7gwj","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}}]}