A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 17 Mar 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Portabilis i-Educar Endpoint educar_servidor_curso_lst.php cross site scripting
First Time appeared Portabilis
Portabilis i-educar
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:*
Vendors & Products Portabilis
Portabilis i-educar
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-03-17T23:32:14.049Z

Updated: 2026-03-17T23:32:14.049Z

Reserved: 2026-03-17T18:32:46.571Z

Link: CVE-2026-4355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-18T00:16:20.683

Modified: 2026-03-18T00:16:20.683

Link: CVE-2026-4355

cve-icon Redhat

No data.