CVE-2025-14212: projectworlds Advanced Library Management System member_search.php sql injection
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /membersearch.php. Executing a manipulation of the argument rollnumber can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14212?
CVE-2025-14212 is classified as a high severity vulnerability due to its potential exploitation via SQL injection.
How do I fix CVE-2025-14212?
To fix CVE-2025-14212, sanitize and validate the input from the 'roll_number' parameter in the /member_search.php file to prevent SQL injection.
Can CVE-2025-14212 be exploited remotely?
Yes, CVE-2025-14212 can be exploited remotely, allowing attackers to execute malicious SQL queries.
What software is affected by CVE-2025-14212?
CVE-2025-14212 affects the Projectworlds Advanced Library Management System version 1.0.
What kind of vulnerability is CVE-2025-14212?
CVE-2025-14212 is an SQL injection vulnerability that allows manipulation of database queries through user input.