CVE-2025-9685
A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Vendor
Product
CWE
Yayın Tarihi
2025-08-30 11:15:35
Güncelleme
2025-09-04 16:50:41
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md
https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.view%60%20Endpoint.md
https://vuldb.com/?ctiid.321897
https://vuldb.com/?id.321897
https://vuldb.com/?submit.638576
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md