SQL Injection Vulnerability in Portabilis i-Educar Product
CVE-2025-10846
5.3MEDIUM
What is CVE-2025-10846?
A critical SQL injection vulnerability exists in Portabilis i-Educar up to version 2.10, specifically within the file /module/ComponenteCurricular/edit. This vulnerability allows malicious actors to manipulate the argument ID, enabling remote exploitation of the system. The exploit has been made public, increasing the risk of attacks on affected systems.
Affected Version(s)
i-Educar 2.0
i-Educar 2.1
i-Educar 2.2