Time-Based SQL Injection in i-Educar School Management Software
CVE-2025-65022
What is CVE-2025-65022?
The i-Educar school management software is vulnerable to an authenticated time-based SQL injection flaw. This issue affects versions 2.10.0 and earlier, allowing attackers with authenticated access to execute arbitrary SQL commands against the application's database. The vulnerability arises from improper handling of the cod_agenda request parameter, which is used in SQL queries without adequate sanitization. This weakness could lead to unauthorized data exposure and manipulation, making it crucial for users to update to the patched version available in commit b473f92.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
i-educar <= 2.10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
