CVE-2025-7110 Overview
CVE-2025-7110 is a reflected cross-site scripting (XSS) vulnerability [CWE-79] in Portabilis i-Educar 2.9.0. The flaw resides in the /intranet/educar_escola_lst.php script within the School Module. Manipulation of the Escola argument allows attackers to inject script content that executes in a victim's browser session.
The issue is remotely exploitable and requires authenticated low-privilege access plus user interaction to trigger. Exploit details have been publicly disclosed. According to the CVE record, the vendor was contacted before public disclosure but did not respond.
Critical Impact
Authenticated attackers can inject JavaScript into the School listing page, enabling session context abuse, phishing, and limited data manipulation within the i-Educar interface.
Affected Products
- Portabilis i-Educar 2.9.0
- Component: School Module (/intranet/educar_escola_lst.php)
- Parameter: Escola
Discovery Timeline
- 2025-07-07 - CVE-2025-7110 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7110
Vulnerability Analysis
The vulnerability is a cross-site scripting flaw in the school listing endpoint of Portabilis i-Educar, an open-source school management platform. The educar_escola_lst.php page reflects the value of the Escola request parameter back into the HTML response without proper encoding or sanitization. As a result, an attacker who can influence the value of that parameter can inject arbitrary HTML or JavaScript into the rendered page.
Execution occurs in the context of any user who loads the crafted URL while authenticated to the i-Educar instance. Because the application is used by school administrators and staff, injected scripts can access authenticated session cookies, submit forged requests, or manipulate the visible interface. The vulnerability is classified as reflected XSS and requires the victim to click a crafted link or visit an attacker-controlled page.
Root Cause
The root cause is missing output encoding on the Escola GET parameter within the school listing view. User-controlled input flows from the HTTP request into the HTML response without being escaped through an appropriate contextual encoder. This violates standard XSS prevention practices for PHP web applications.
Attack Vector
Exploitation proceeds over the network against the affected educar_escola_lst.php endpoint. An attacker crafts a URL containing a malicious Escola parameter value and delivers it to a logged-in i-Educar user through phishing, chat, or a malicious page. When the target loads the URL, the injected payload executes in the browser under the i-Educar origin. Public proof-of-concept details are available in the GitHub PoC Repository and the VulDB entry #315021.
Detection Methods for CVE-2025-7110
Indicators of Compromise
- Web server access log entries showing requests to /intranet/educar_escola_lst.php containing HTML tags, javascript: URIs, or encoded script payloads in the Escola parameter.
- Unusual referrers or external hosts sending users to the educar_escola_lst.php endpoint with long or encoded query strings.
- Browser console errors or Content Security Policy (CSP) violations reported by users interacting with the School Module.
Detection Strategies
- Deploy web application firewall (WAF) rules that inspect the Escola query parameter for script tags, event handlers (onerror=, onload=), and JavaScript scheme URIs.
- Enable server-side request logging with full query strings and periodically hunt for reflected XSS patterns against i-Educar endpoints.
- Use browser-side CSP reporting to identify script executions that violate the expected script origins on i-Educar pages.
Monitoring Recommendations
- Correlate authenticated session activity with anomalous outbound requests originating from staff browsers immediately after visiting the School Module.
- Monitor for account behavior changes such as unexpected privilege modifications or new user creation performed shortly after a suspicious educar_escola_lst.php request.
- Track the VulDB advisory #315021 (CTIID) for updates on patch availability or exploitation activity.
How to Mitigate CVE-2025-7110
Immediate Actions Required
- Restrict access to the i-Educar /intranet/ path to trusted internal networks or VPN users until a vendor fix is available.
- Enforce a strict Content Security Policy that disallows inline scripts and limits script sources to trusted origins.
- Train school staff to avoid clicking untrusted links that reference i-Educar URLs, particularly those with long Escola query strings.
Patch Information
No vendor patch is referenced in the CVE record at the time of publication. The Portabilis i-Educar project should be monitored for security releases addressing the educar_escola_lst.php reflected XSS. Upgrade to any release later than 2.9.0 that includes fixes for CWE-79 in the School Module.
Workarounds
- Add a WAF or reverse proxy rule that rejects requests to educar_escola_lst.php when the Escola parameter contains <, >, ", or javascript: sequences.
- Apply a local patch that encodes the Escola parameter with htmlspecialchars($value, ENT_QUOTES, 'UTF-8') before rendering it in the response.
- Enforce short session timeouts and require reauthentication for privileged operations to limit XSS impact.
# Example ModSecurity rule blocking script payloads in the Escola parameter
SecRule ARGS:Escola "@rx (?i)(<script|javascript:|onerror=|onload=)" \
"id:1007110,phase:2,deny,status:403,log,\
msg:'CVE-2025-7110 i-Educar Escola XSS attempt blocked'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.