{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-7871","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-07-19T05:52:59.414Z","datePublished":"2025-07-20T06:02:05.813Z","dateUpdated":"2026-10-09T16:41:20.873Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-10-09T16:41:20.873Z"},"title":"Portabilis i-Diario conteudos cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"Portabilis","product":"i-Diario","versions":[{"version":"1.5.0","status":"affected"}],"cpes":["cpe:2.3:a:portabilis:i-diario:*:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in Portabilis i-Diario 1.5.0. The impacted element is an unknown function of the file /conteudos. Performing a manipulation of the argument filter[by_description] results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The patch is named d076c112b45e3b3e41cbe11de27949b491d922c2. It is recommended to apply a patch to fix this issue. The vendor confirms: \"The searched term is now rendered escaped in the autocomplete widget, and the content tags are rendered through output-escaped templates, so an injected payload is displayed as inert text instead of being executed.\""}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C"}}],"timeline":[{"time":"2025-07-02T00:00:00.000Z","lang":"en","value":"Vulnerability found"},{"time":"2025-07-19T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-07-19T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-10-09T18:46:12.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Natan Morette (CVE-Hunters)","type":"finder"},{"lang":"en","value":"nmmorette (VulDB User)","type":"reporter"},{"lang":"en","value":"nmmorette (VulDB User)","type":"analyst"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/316984","name":"VDB-316984 | Portabilis i-Diario conteudos cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/316984/cti","name":"VDB-316984 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2025-7871","name":"CVE-2025-7871 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/607948","name":"Submit #607948 | Portabilis i-diario 1.5.0 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://github.com/CVE-Hunters/CVE/blob/main/i-diario/CVE-2025-7871.md","tags":["exploit"]},{"url":"https://github.com/portabilis/i-diario/commit/d076c112b45e3b3e41cbe11de27949b491d922c2","tags":["patch"]},{"url":"https://github.com/portabilis/i-diario/","tags":["product"]}],"tags":["x_open-source"],"x_generator":["VulDB PVTS v202610"]},"adp":[{"references":[{"url":"https://github.com/CVE-Hunters/CVE/blob/main/i-diario/CVE-2025-7871.md","tags":["exploit"]},{"url":"https://vuldb.com/?submit.607948","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-07-22T13:52:05.473258Z","id":"CVE-2025-7871","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-07-22T13:52:08.028Z"}}]}}