CVE-2025-13256: projectworlds Advanced Library Management System borrow.php sql injection
A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument rollnumber can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13256?
CVE-2025-13256 has been classified with a high severity due to the potential for SQL injection vulnerabilities.
How do I fix CVE-2025-13256?
To fix CVE-2025-13256, sanitize user inputs and use prepared statements for SQL queries in the Advanced Library Management System.
Which systems are affected by CVE-2025-13256?
CVE-2025-13256 specifically affects version 1.0 of the Projectworlds Advanced Library Management System.
Can CVE-2025-13256 be exploited remotely?
Yes, CVE-2025-13256 allows for remote exploitation through crafted SQL injection attacks.
What is the main vulnerability in CVE-2025-13256?
The main vulnerability in CVE-2025-13256 is SQL injection through manipulation of the 'roll_number' argument in the /borrow.php file.