CVE-2025-13253: projectworlds Advanced Library Management System add_librarian.php sql injection
A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /addlibrarian.php. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13253?
CVE-2025-13253 has a high severity rating due to its potential for SQL injection.
How can I fix CVE-2025-13253?
To fix CVE-2025-13253, ensure proper input validation and use prepared statements to prevent SQL injection in the /add_librarian.php file.
What are the potential impacts of CVE-2025-13253?
The impacts of CVE-2025-13253 include unauthorized access to sensitive data and potential control over the database.
Is CVE-2025-13253 exploitable remotely?
Yes, CVE-2025-13253 can be exploited remotely, allowing attackers to gain access through the vulnerable /add_librarian.php endpoint.
Which software is affected by CVE-2025-13253?
CVE-2025-13253 affects the Advanced Library Management System version 1.0 developed by Projectworlds.