CVE-2025-12237: projectworlds Advanced Library Management System index.php sql injection
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such manipulation of the argument keywords leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12237?
CVE-2025-12237 is classified as a critical severity vulnerability due to its potential for SQL injection, which can be exploited remotely.
How do I fix CVE-2025-12237?
To fix CVE-2025-12237, update the Advanced Library Management System to the latest version or implement input validation and prepared statements to mitigate SQL injection.
What type of vulnerability is CVE-2025-12237?
CVE-2025-12237 is a SQL injection vulnerability that can be exploited by manipulating the 'keywords' argument in the /index.php file.
Who is affected by CVE-2025-12237?
CVE-2025-12237 affects users of the Projectworlds Advanced Library Management System version 1.0.
Can CVE-2025-12237 be exploited remotely?
Yes, CVE-2025-12237 can be exploited remotely, allowing an attacker to execute SQL injection attacks on vulnerable installations.