PT-2025-35354 · Unknown · Portabilis I-Educar
Marceloqz
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9685
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Portabilis i-Educar versions up to 2.10
Description
A vulnerability exists in Portabilis i-Educar up to version 2.10, specifically within the
/module/AreaConhecimento/view file of the Listagem de áreas de conhecimento Page component. Manipulation of the ID argument can lead to a SQL injection. The attack can be executed remotely. The exploit is publicly available.Recommendations
Versions prior to 2.10 should be updated.
As a temporary workaround, restrict access to the
/module/AreaConhecimento/view file.
Avoid using the ID parameter in the affected component until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Portabilis I-Educar