PT-2025-35355 · Portabilis · Portabilis I-Educar

Marceloqz

·

Published

2025-08-30

·

Updated

2025-08-30

·

CVE-2025-9686

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

Portabilis i-Educar versions up to 2.10

Description:

A security flaw has been discovered in Portabilis i-Educar. The issue affects processing of the file `/module/AreaConhecimento/edit` of the Listagem de áreas de conhecimento Page component. Manipulation of the `ID` argument results in SQL injection. The attack is possible to be carried out remotely. The exploit has been released to the public.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9686

Affected Products

Portabilis I-Educar