SQL Injection Vulnerability in Portabilis i-Educar Product
CVE-2025-10012
Key Information:
- Vendor
Portabilis
- Status
- Vendor
- CVE Published:
- 5 September 2025
Badges
What is CVE-2025-10012?
A vulnerability exists in Portabilis i-Educar, specifically within the educar_historico_escolar_lst.php file. An unknown function related to the argument ref_cod_aluno is susceptible to manipulation, allowing for SQL injection attacks. This vulnerability can be exploited remotely, posing a significant risk to data integrity and security. Public disclosures of this exploit have been made, indicating potential for active exploitation.
Affected Version(s)
i-Educar 2.0
i-Educar 2.1
i-Educar 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved