SQL Injection Vulnerability in Portabilis i-Educar Software
CVE-2025-9686

5.3MEDIUM

Key Information:

Vendor

Portabilis

Status
Vendor
CVE Published:
30 August 2025

What is CVE-2025-9686?

A security flaw exists in Portabilis i-Educar prior to version 2.10, where improper processing within the Listagem de áreas de conhecimento Page allows SQL injection through manipulated ID arguments. This vulnerability can be exploited remotely, enabling attackers to execute arbitrary SQL commands on the database, compromising the integrity and confidentiality of the application data. An exploit for this vulnerability has been publicly released, underscoring the urgency for affected users to take necessary security measures.

Affected Version(s)

i-Educar 2.0

i-Educar 2.1

i-Educar 2.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

marceloQz (VulDB User)
marceloQz (VulDB User)
.
CVE-2025-9686 : SQL Injection Vulnerability in Portabilis i-Educar Software