PT-2025-35176 · Unknown · Portabilis I-Educar

Marceloqz

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-9607

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portabilis i-Educar versions up to 2.10
Description A flaw exists in Portabilis i-Educar up to version 2.10, related to SQL injection. The issue is located in the /module/TabelaArredondamento/view file within the Tabelas de Arredondamento Page component. Manipulation of the ID argument can trigger the injection. The attack can be launched remotely.
Recommendations Versions prior to 2.10 should be updated. Consider restricting access to the /module/TabelaArredondamento/view file as a temporary workaround. Avoid using the ID parameter in the affected file until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9607

Affected Products

Portabilis I-Educar