VulnerabilityAnalyzed
CVE-2025-9685
A vulnerability was identified in Portabilis i-Educar up to 2.10.
LOW 2.1EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- portabilis/i-educar
- Source
- cna@vuldb.com
References
- https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.mdExploit, Third Party Advisory
- https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20%60id%60%20Parameter%20on%20%60.module.AreaConhecimento.view%60%20Endpoint.mdBroken Link
- https://vuldb.com/?ctiid.321897Permissions Required, VDB Entry
- https://vuldb.com/?id.321897Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.638576Third Party Advisory, VDB Entry
- https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9685.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.