CVE-2025-10844
MEDIUMPortabilis i-Educar < 2.10.0 - SQL Injection via /module/Cadastro/aluno is Argument
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-10844. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains a detailed technical writeup for CVE-2025-10844, focusing on a directory traversal vulnerability in i-Educar. It includes step-by-step exploitation details, screenshots, and references, demonstrating a clear understanding of the vulnerability mechanics.
Description
A vulnerability has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/Cadastro/aluno. The manipulation of the argument is leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Exploits (1)
The repository contains a detailed technical writeup for CVE-2025-10844, focusing on a directory traversal vulnerability in i-Educar. It includes step-by-step exploitation details, screenshots, and references, demonstrating a clear understanding of the vulnerability mechanics.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L