CVE-2025-9686 | Portabilis i-Educar up to 2.10 Listagem de áreas de conhecimento Page edit ID sql injection
A vulnerability identified as critical has been detected in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component Listagem de áreas de conhecimento Page. Performing manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2025-9686. The attack is possible to be carried out remotely. Moreover, an exploit is present.