SQL Injection Vulnerability in i-Educar School Management Software
CVE-2025-65023
What is CVE-2025-65023?
In i-Educar versions 2.10.0 and earlier, an SQL injection vulnerability has been identified within the intranet functionality. This flaw resides in the handling of the cod_funcionario_vinculo GET parameter inside the funcionario_vinculo_cad.php script. If exploited, it allows an authenticated attacker to execute arbitrary SQL commands on the application's database, posing significant risks to the integrity and confidentiality of the stored data. This issue stems from a lack of input sanitization, enabling attackers to manipulate database queries effectively. The vulnerability has since been addressed in a subsequent patch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
i-educar <= 2.10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
