PT-2025-35175 · Portabilis · I-Educar

Marceloqz

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-9606

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

Portabilis i-Educar versions prior to 2.11

Description:

A SQL injection issue exists in an unknown functionality of the file `/intranet/agenda preferencias.php`. Manipulation of the `cod agenda` argument can trigger the issue. The attack can be initiated remotely, and the exploit is publicly available.

Recommendations:

Update to version 2.11 or later.

As a temporary workaround, restrict access to the `/intranet/agenda preferencias.php` file.

Sanitize the `cod agenda` argument to prevent SQL injection.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9606

Affected Products

I-Educar