CVE-2025-13254: projectworlds Advanced Library Management System add_member.php sql injection
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /addmember.php. Such manipulation of the argument rollnumber leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13254?
CVE-2025-13254 is classified as a medium-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-13254?
To fix CVE-2025-13254, sanitize and validate the input parameters in the /add_member.php file to prevent SQL injection.
What systems are affected by CVE-2025-13254?
CVE-2025-13254 affects version 1.0 of the Projectworlds Advanced Library Management System.
Can CVE-2025-13254 be exploited remotely?
Yes, CVE-2025-13254 can be exploited remotely by manipulating the roll_number argument.
What type of vulnerability is CVE-2025-13254?
CVE-2025-13254 is an SQL injection vulnerability that can potentially compromise the database.