CVE-2025-13278: projectworlds Advanced Library Management System borrowed_book_search.php sql injection
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowedbooksearch.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13278?
CVE-2025-13278 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-13278?
To fix CVE-2025-13278, sanitize and validate all user inputs, particularly the 'datefrom' and 'dateto' parameters in the /borrowed_book_search.php file.
What type of vulnerability is CVE-2025-13278?
CVE-2025-13278 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2025-13278 be exploited remotely?
Yes, CVE-2025-13278 can be exploited remotely by an attacker with knowledge of the vulnerable parameters.
What software is affected by CVE-2025-13278?
CVE-2025-13278 affects the Projectworlds Advanced Library Management System version 1.0.