CVE-2025-10846: Portabilis i-Educar edit sql injection
A vulnerability was determined in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10846?
CVE-2025-10846 has a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-10846?
To fix CVE-2025-10846, upgrade Portabilis i-Educar to version 2.11 or later.
What are the potential impacts of CVE-2025-10846?
CVE-2025-10846 can allow an attacker to execute arbitrary SQL commands, leading to unauthorized data access.
Is CVE-2025-10846 exploitable remotely?
Yes, CVE-2025-10846 can be exploited remotely by manipulating the ID argument in the affected file.
Which versions of Portabilis i-Educar are affected by CVE-2025-10846?
Portabilis i-Educar versions up to and including 2.10 are affected by CVE-2025-10846.