PT-2025-47474 · I-Educar · I-Educar

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-65023

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions i-Educar versions prior to 2.10.0
Description i-Educar is school management software. A time-based SQL injection exists in the ieducar/intranet/funcionario vinculo cad.php script for authenticated users. An attacker with an authenticated session can execute arbitrary SQL commands against the application's database. The issue is due to the improper handling of the cod funcionario vinculo GET parameter, which is directly concatenated into an SQL query without proper sanitization.
Recommendations Update i-Educar to a version later than 2.10.0.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65023
GHSA-8RV6-X8H9-FJFC

Affected Products

I-Educar