A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component Listagem de áreas de conhecimento Page. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
References
Link | Resource |
---|---|
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9686.md | Exploit Third Party Advisory |
https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.edit%60%20Endpoint.md | Broken Link |
https://vuldb.com/?ctiid.321898 | Permissions Required VDB Entry |
https://vuldb.com/?id.321898 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.638577 | Third Party Advisory VDB Entry |
https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9686.md | Exploit Third Party Advisory |
Configurations
History
04 Sep 2025, 16:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* | |
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9686.md - Exploit, Third Party Advisory | |
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.edit%60%20Endpoint.md - Broken Link | |
References | () https://vuldb.com/?ctiid.321898 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.321898 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.638577 - Third Party Advisory, VDB Entry | |
First Time |
Portabilis
Portabilis i-educar |
02 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9686.md - |
30 Aug 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-30 12:15
Updated : 2025-09-04 16:50
NVD link : CVE-2025-9686
Mitre link : CVE-2025-9686
CVE.ORG link : CVE-2025-9686
JSON object : View
Products Affected
portabilis
- i-educar