A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
References
Link | Resource |
---|---|
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md | Exploit Third Party Advisory |
https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.view%60%20Endpoint.md | Broken Link |
https://vuldb.com/?ctiid.321897 | Permissions Required VDB Entry |
https://vuldb.com/?id.321897 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.638576 | Third Party Advisory VDB Entry |
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md | Exploit Third Party Advisory |
Configurations
History
04 Sep 2025, 16:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md - Exploit, Third Party Advisory | |
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.view%60%20Endpoint.md - Broken Link | |
References | () https://vuldb.com/?ctiid.321897 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.321897 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.638576 - Third Party Advisory, VDB Entry | |
First Time |
Portabilis
Portabilis i-educar |
|
CPE | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* |
02 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.md - |
30 Aug 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-30 11:15
Updated : 2025-09-04 16:50
NVD link : CVE-2025-9685
Mitre link : CVE-2025-9685
CVE.ORG link : CVE-2025-9685
JSON object : View
Products Affected
portabilis
- i-educar