A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of …
Medium CVSS 6.3
Summary
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.12 addresses this issue. Upgrading the affected component is advised. The vendor confirms: "The reported attack vector was tested against the corr…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9606.md Exploit
- https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20cod_agenda%20Parameter%20on%20agenda_preferencias.php%20Endpoint.md#poc Broken Link
- https://github.com/portabilis/i-educar/tree/2.12
- https://vuldb.com/cve/CVE-2025-9606
- https://vuldb.com/submit/636577
- https://vuldb.com/vuln/321784
- https://vuldb.com/vuln/321784/cti
- https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9606.md Exploit
- https://vuldb.com/?submit.636577 Third Party Advisory
Timeline
- nvd_ingest NVD