A vulnerability identified as problematic has been detected in Portabilis i-Diario up to 1.5.0. This vulnerability affects unknown code of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. The manipulation of the argument Parecer/Conteúdos/Objetivos leads to cross site scripting.
This vulnerability was named CVE-2025-9106. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.