PT-2025-35175 · Portabilis · I-Educar

Marceloqz

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-9606

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar versions prior to 2.11
Description A SQL injection issue exists in an unknown functionality of the file /intranet/agenda preferencias.php. Manipulation of the cod agenda argument can trigger the issue. The attack can be initiated remotely, and the exploit is publicly available.
Recommendations Update to version 2.11 or later. As a temporary workaround, restrict access to the /intranet/agenda preferencias.php file. Sanitize the cod agenda argument to prevent SQL injection.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9606

Affected Products

I-Educar