PT-2025-35353 · Unknown · Portabilis I-Educar
Marceloqz
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9684
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Portabilis i-Educar versions up to 2.10
Description
A vulnerability exists in Portabilis i-Educar up to version 2.10, specifically within the
/module/FormulaMedia/edit file of the Formula de Cálculo de Média Page component. Manipulation of the ID argument can lead to SQL injection. Remote exploitation is possible, and the exploit has been publicly disclosed.Recommendations
Versions prior to 2.10 should be updated.
As a temporary workaround, restrict access to the
/module/FormulaMedia/edit file.
Sanitize the ID argument to prevent SQL injection.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Portabilis I-Educar