PT-2025-47475 · I-Educar · I-Educar

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-65024

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions i-Educar versions prior to 2.10.0
Description i-Educar is school management software with a flaw that allows an authenticated attacker to execute arbitrary SQL commands against the application's database. This is due to a time-based SQL injection in the ieducar/intranet/agenda admin cad.php script. The issue stems from the improper handling of the cod agenda GET parameter, which is directly incorporated into an SQL query without sufficient sanitization.
Recommendations Update i-Educar to a version later than 2.10.0.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65024
GHSA-6C8P-XQCV-RGHX

Affected Products

I-Educar