PT-2025-39148 · Unknown · Portabilis I-Educar
Karina Gante
+1
·
Published
2025-09-23
·
Updated
2025-10-28
·
CVE-2025-10845
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Portabilis i-Educar versions prior to 2.11
Description
A flaw exists in Portabilis i-Educar that allows for remote code execution. The issue stems from a SQL injection vulnerability within the
/module/ComponenteCurricular/view file. Manipulation of the ID parameter can lead to unauthorized access and potential compromise. The exploit for this issue has been publicly released.Recommendations
Update to version 2.11 or later.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Portabilis I-Educar