---
id: CVE-2023-5578
title: A vulnerability was detected in Portábilis i-Educar up to 2.7.5
summary: >-
  A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is
  an unknown function of the file \intranet\agenda_imprimir.php of the component
  HTTP GET Request Handler. The manipulation of the argument cod_agenda with the
  in…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: portabilis
product: i-educar
affected:
  - i-educar <= 2.7.5
published: '2023-10-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T03:17:03.637'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5578'
references:
  - url: 'https://github.com/portabilis/i-educar'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2023-5578'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/217053'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/649873'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/242143'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/242143/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.242143'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?id.242143'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00416
epssPercentile: 0.33188
ingestedAt: '2026-09-15T03:19:45.414Z'
---

## Overview

A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> <script>alert(document.cookie)</script> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: "This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed."

## Affected

- `i-educar <= 2.7.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
