A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
References
| Link | Resource |
|---|---|
| https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md | Exploit Third Party Advisory |
| https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.view%60%20Endpoint.md | Broken Link |
| https://vuldb.com/?ctiid.321897 | Permissions Required VDB Entry |
| https://vuldb.com/?id.321897 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.638576 | Third Party Advisory VDB Entry |
| https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-08-30 11:15
Updated : 2025-09-04 16:50
NVD link : CVE-2025-9685
Mitre link : CVE-2025-9685
CVE.ORG link : CVE-2025-9685
JSON object : View
Products Affected
portabilis
- i-educar
