PT-2025-35175 · Portabilis · I-Educar
Marceloqz
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9606
Marceloqz
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9606
6.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Portabilis i-Educar versions prior to 2.11
Description:
A SQL injection issue exists in an unknown functionality of the file `/intranet/agenda preferencias.php`. Manipulation of the `cod agenda` argument can trigger the issue. The attack can be initiated remotely, and the exploit is publicly available.
Recommendations:
Update to version 2.11 or later.
As a temporary workaround, restrict access to the `/intranet/agenda preferencias.php` file.
Sanitize the `cod agenda` argument to prevent SQL injection.
Exploit
Fix
Special Elements Injection
SQL injection