CVE-2025-14210: projectworlds Advanced Library Management System delete_member.php sql injection
A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /deletemember.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14210?
CVE-2025-14210 has a high severity due to its potential for SQL injection attacks.
How do I fix CVE-2025-14210?
To fix CVE-2025-14210, validate and sanitize user inputs in the /delete_member.php file to prevent SQL injection.
What impacts does CVE-2025-14210 have on the Advanced Library Management System?
CVE-2025-14210 allows remote attackers to manipulate the user_id argument, potentially compromising database security.
Can CVE-2025-14210 be exploited remotely?
Yes, CVE-2025-14210 can be exploited remotely, making it a critical concern for users of the application.
What is the affected component related to CVE-2025-14210?
The affected component of CVE-2025-14210 is the /delete_member.php file within the Advanced Library Management System.