A vulnerability categorized as critical has been discovered in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the component Tabelas de Arredondamento Page. Executing manipulation of the argument ID can lead to sql injection.

The identification of this vulnerability is CVE-2025-9607. The attack may be launched remotely. Furthermore, there is an exploit available.