A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/view. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://karinagante.github.io/cve-2025-9532/ | Exploit Third Party Advisory |
https://karinagante.github.io/cve-2025-9532/#proof-of-concept-poc | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.321551 | Permissions Required VDB Entry |
https://vuldb.com/?id.321551 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.635801 | Third Party Advisory VDB Entry |
https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md | Broken Link |
https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md#poc | Broken Link |
https://vuldb.com/?submit.635801 | Third Party Advisory VDB Entry |
Configurations
History
04 Sep 2025, 18:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://karinagante.github.io/cve-2025-9532/ - Exploit, Third Party Advisory | |
References | () https://karinagante.github.io/cve-2025-9532/#proof-of-concept-poc - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.321551 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.321551 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.635801 - Third Party Advisory, VDB Entry | |
References | () https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md - Broken Link | |
References | () https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md#poc - Broken Link | |
CPE | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* | |
First Time |
Portabilis
Portabilis i-educar |
29 Aug 2025, 16:24
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Aug 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md - | |
References | () https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/12.md#poc - | |
References | () https://vuldb.com/?submit.635801 - |
27 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-27 14:15
Updated : 2025-09-04 18:35
NVD link : CVE-2025-9532
Mitre link : CVE-2025-9532
CVE.ORG link : CVE-2025-9532
JSON object : View
Products Affected
portabilis
- i-educar