---
id: CVE-2025-10012
title: A security vulnerability has been detected in Portabilis i-Educar up to 2.10
summary: >-
  A security vulnerability has been detected in Portabilis i-Educar up to 2.10.
  The impacted element is an unknown function of the file
  educar_historico_escolar_lst.php. Such manipulation of the argument
  ref_cod_aluno leads to sql injectio…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: portabilis
product: i-educar
affected:
  - i-educar <= 2.10.0
published: '2025-09-05'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T09:16:43.287'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10012'
references:
  - url: 'https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10012.md'
    label: cna@vuldb.com
  - url: >-
      https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20ref_cod_aluno%20Parameter%20on%20educar_historico_escolar_lst.php%20Endpoint.md
    label: cna@vuldb.com
  - url: 'https://github.com/portabilis/i-educar/tree/2.12'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2025-10012'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/643549'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/322737'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/322737/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-09-05T14:58:39.815229Z'
epss: 0.00369
epssPercentile: 0.30756
ingestedAt: '2026-09-15T08:34:10.548Z'
---

## Overview

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.12 is sufficient to resolve this issue. It is advisable to upgrade the affected component. The vendor confirms, that "[t]he reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced".

## Affected

- `i-educar <= 2.10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
