SQL Injection Vulnerability in Portabilis i-Educar Software
CVE-2025-9686
What is CVE-2025-9686?
A security flaw exists in Portabilis i-Educar prior to version 2.10, where improper processing within the Listagem de áreas de conhecimento Page allows SQL injection through manipulated ID arguments. This vulnerability can be exploited remotely, enabling attackers to execute arbitrary SQL commands on the database, compromising the integrity and confidentiality of the application data. An exploit for this vulnerability has been publicly released, underscoring the urgency for affected users to take necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
i-Educar 2.0
i-Educar 2.1
i-Educar 2.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
