CVE-2025-13572: projectworlds Advanced Library Management System delete_admin.php sql injection
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /deleteadmin.php. The manipulation of the argument adminid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13572?
CVE-2025-13572 is rated as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-13572?
To fix CVE-2025-13572, ensure that proper input validation and parameterized queries are implemented in the affected /delete_admin.php file.
What software is affected by CVE-2025-13572?
CVE-2025-13572 affects the projectworlds Advanced Library Management System version 1.0.
Can CVE-2025-13572 be exploited remotely?
Yes, CVE-2025-13572 allows for remote exploitation through SQL injection via the admin_id argument.
What is the consequence of exploiting CVE-2025-13572?
Exploiting CVE-2025-13572 can lead to unauthorized database access and manipulation of sensitive data.