PT-2025-47473 · I-Educar · I-Educar

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-65022

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions i-Educar versions prior to 2.10.0
Description i-Educar is school management software with a flaw that allows an authenticated attacker to execute arbitrary SQL commands against the application's database. This is due to improper handling of the cod agenda request parameter in the ieducar/intranet/agenda.php script, which is directly concatenated into SQL queries without sufficient sanitization. The vulnerability is a time-based SQL injection.
Recommendations Update i-Educar to a version later than 2.10.0.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65022
GHSA-4HRJ-5GWX-R4W4

Affected Products

I-Educar