CVE-2025-7113 Overview
CVE-2025-7113 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in Portabilis i-Educar 2.9.0. The flaw resides in the Curricular Components Module, specifically the /module/ComponenteCurricular/edit?id=ID endpoint. Attackers can inject malicious script payloads through the Nome parameter, which the application renders without proper sanitization. Exploitation requires low-privilege authenticated access and user interaction to trigger the injected script. Public proof-of-concept details were disclosed, and the vendor did not respond to disclosure attempts. The vulnerability affects the school management workflows used by educational institutions relying on i-Educar.
Critical Impact
An authenticated attacker with low privileges can store JavaScript payloads in curricular component records, executing arbitrary script in the browsers of educators or administrators who view the affected page.
Affected Products
- Portabilis i-Educar 2.9.0
- Curricular Components Module (ComponenteCurricular edit function)
- Deployments exposing the /module/ComponenteCurricular/edit endpoint to authenticated users
Discovery Timeline
- 2025-07-07 - CVE-2025-7113 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7113
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw in the Curricular Components Module of Portabilis i-Educar 2.9.0. The affected endpoint /module/ComponenteCurricular/edit?id=ID accepts user-supplied data through the Nome (Name) field. The application fails to encode or sanitize this input before persisting and rendering it back in the administrative interface. When another authenticated user views the modified curricular component, the injected script executes within their browser session.
Because i-Educar is deployed by schools and municipal education departments, the affected interfaces are typically accessed by staff with elevated privileges. Successful exploitation can lead to session token theft, unauthorized administrative actions, and redirection to attacker-controlled resources. See the VulDB advisory and the public PoC repository for further technical detail.
Root Cause
The root cause is missing output encoding on the Nome parameter within the ComponenteCurricular edit workflow. The application trusts input submitted by authenticated users and stores it verbatim. When the record is later rendered in the module's edit or listing views, the raw value is emitted into HTML context without contextual escaping.
Attack Vector
An attacker with a low-privileged authenticated account submits a crafted Nome value containing HTML or JavaScript to /module/ComponenteCurricular/edit?id=ID. The payload is stored in the curricular component record. Exploitation requires a victim user to load the affected page, at which point the script executes in the victim's authenticated session. The attack is delivered over the network and does not require local access.
No verified exploit code is republished here. Refer to the public PoC repository for the disclosed request format.
Detection Methods for CVE-2025-7113
Indicators of Compromise
- HTTP POST or GET requests to /module/ComponenteCurricular/edit containing HTML tags such as <script>, <img onerror=, or <svg onload= in the Nome parameter.
- Curricular component records whose Nome field contains angle brackets, JavaScript URIs, or event handler attributes.
- Outbound requests from browser sessions of i-Educar administrators to unfamiliar external hosts shortly after opening a curricular component page.
Detection Strategies
- Inspect web server access logs for requests to the ComponenteCurricular module with suspicious characters in query strings or POST bodies.
- Query the i-Educar database for curricular component names containing <, >, javascript:, or on[event]= substrings.
- Deploy a web application firewall (WAF) signature that flags XSS payload patterns targeting the Nome parameter.
Monitoring Recommendations
- Enable and centralize application, web server, and reverse proxy logs covering the /module/ComponenteCurricular/* paths.
- Alert on administrator sessions performing atypical actions immediately after loading curricular component pages.
- Track user-agent, source IP, and session anomalies for accounts with access to the Curricular Components Module.
How to Mitigate CVE-2025-7113
Immediate Actions Required
- Restrict access to the Curricular Components Module to trusted, minimum-necessary user roles until a patch is available.
- Audit existing curricular component records for stored payloads and sanitize any values containing HTML or script fragments.
- Enforce strong session controls, including short session timeouts and re-authentication for administrative actions.
- Educate administrative users to avoid opening curricular component records from untrusted sources or newly created accounts.
Patch Information
At the time of NVD publication, no vendor patch has been released. According to the disclosure, Portabilis was contacted but did not respond. Monitor the Portabilis i-Educar GitHub project for security updates and apply fixes as soon as they become available.
Workarounds
- Deploy a WAF rule that blocks requests to /module/ComponenteCurricular/edit containing <, >, or javascript: sequences in the Nome parameter.
- Add a strict Content Security Policy (CSP) header that disallows inline scripts and restricts script sources to trusted origins.
- Set the HttpOnly and Secure flags on session cookies to reduce the impact of script execution in an authenticated context.
- Limit network exposure of the i-Educar administrative interface to internal networks or VPN users only.
# Example NGINX Content Security Policy header to reduce XSS impact
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
