CVE-2025-8918 Overview
CVE-2025-8918 is a stored cross-site scripting (XSS) vulnerability affecting Portabilis i-Educar through version 2.10. The flaw resides in /intranet/educar_instituicao_cad.php within the Editar Page component. Attackers can inject malicious script content through the neighborhood name argument, which the application stores and later renders without proper sanitization.
The vulnerability is remotely exploitable and requires an authenticated user with high privileges plus victim interaction to trigger the payload. The vendor was contacted before public disclosure but did not respond. The exploit details are publicly available.
Critical Impact
Authenticated attackers can persist JavaScript payloads in the institution registration workflow, enabling session-context script execution against other i-Educar users who view the affected records.
Affected Products
- Portabilis i-Educar versions up to and including 2.10
- Component: Editar Page (/intranet/educar_instituicao_cad.php)
- Vulnerable parameter: neighborhood name
Discovery Timeline
- 2025-08-13 - CVE-2025-8918 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8918
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw [CWE-79] in the institution registration workflow of Portabilis i-Educar. The educar_instituicao_cad.php endpoint accepts a neighborhood name input as part of the address fields when editing an institution record. The application persists the raw value to the backend database and echoes it back into HTML responses without contextual output encoding.
When another user opens the affected record, the browser parses the stored payload as executable JavaScript in the origin of the i-Educar application. Because i-Educar is a school-management platform, stored payloads can reach administrators, secretariat staff, and teachers who routinely review institution data.
Exploitation requires high-privilege authenticated access plus interaction from a victim user viewing the affected page, which limits the practical attack surface. However, once a payload is stored, it executes against every subsequent viewer until an administrator removes it.
Root Cause
The root cause is missing input validation and output encoding on the neighborhood name parameter in educar_instituicao_cad.php. The application trusts the neighborhood field as free-form text and does not apply HTML entity encoding when rendering the value in the edit page markup.
Attack Vector
An attacker with authenticated access to the institution editing interface submits a crafted neighborhood value containing JavaScript. The payload is stored server-side. When any authorized user later loads the institution record, their browser executes the stored script under the i-Educar session context. See the public GitHub XSS report for reproduction details.
No verified proof-of-concept code is included here. Refer to the referenced advisory for the sanitized payload sample.
Detection Methods for CVE-2025-8918
Indicators of Compromise
- HTTP POST requests to /intranet/educar_instituicao_cad.php containing HTML tags, <script> fragments, or JavaScript event handlers (onerror, onload, onmouseover) in the neighborhood field.
- Institution records whose stored neighborhood value contains angle brackets, encoded script tags, or URI schemes such as javascript:.
- Unexpected outbound requests originating from browser sessions of staff users shortly after loading an institution record.
Detection Strategies
- Review database rows in the institution/address tables for neighborhood values containing HTML metacharacters or scripting keywords.
- Inspect web server access logs for requests to educar_instituicao_cad.php that include URL-encoded payloads such as %3Cscript%3E or %3Cimg.
- Deploy a Content Security Policy (CSP) in report-only mode to surface inline script executions originating from stored data.
Monitoring Recommendations
- Alert on any modification to institution records made by accounts that do not normally perform administrative edits.
- Correlate authentication events with subsequent edits to educar_instituicao_cad.php to identify anomalous privilege usage.
- Monitor for browser-generated outbound connections to attacker-controlled domains from authenticated i-Educar sessions.
How to Mitigate CVE-2025-8918
Immediate Actions Required
- Restrict access to the institution editing interface to a minimal set of trusted administrative accounts.
- Audit existing institution records and sanitize or purge neighborhood values containing HTML or JavaScript syntax.
- Deploy a strict Content Security Policy that disallows inline scripts on i-Educar pages to limit payload execution.
Patch Information
At the time of NVD publication, no vendor patch or advisory was available. Portabilis did not respond to the pre-disclosure contact according to the VulDB entry. Monitor the Portabilis i-Educar repository for a fix and apply it as soon as it ships.
Workarounds
- Place a web application firewall (WAF) rule in front of /intranet/educar_instituicao_cad.php that blocks requests containing script tags or JavaScript event handlers in address fields.
- Enforce server-side input validation on neighborhood values, rejecting characters such as <, >, ", and ' at the request handler level.
- Apply HTML entity encoding to all address fields wherever they are rendered in the i-Educar user interface.
# Example ModSecurity rule to block XSS payloads on the vulnerable endpoint
SecRule REQUEST_URI "@contains /intranet/educar_instituicao_cad.php" \
"phase:2,chain,deny,status:403,id:1008918,\
msg:'CVE-2025-8918 XSS attempt in i-Educar neighborhood field'"
SecRule ARGS "@rx (?i)(<script|onerror=|onload=|javascript:)" \
"t:none,t:urlDecodeUni,t:htmlEntityDecode"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.