CVE-2025-14527: projectworlds Advanced Library Management System view_book.php sql injection
A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /viewbook.php. Executing a manipulation of the argument bookid can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14527?
CVE-2025-14527 is classified as a medium severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-14527?
To fix CVE-2025-14527, ensure that input validation and parameterized queries are implemented in the /view_book.php file.
What is affected by CVE-2025-14527?
CVE-2025-14527 affects the projectworlds Advanced Library Management System version 1.0.
Can CVE-2025-14527 be exploited remotely?
Yes, CVE-2025-14527 can be exploited remotely by manipulating the book_id parameter.
What type of vulnerability is CVE-2025-14527?
CVE-2025-14527 is an SQL injection vulnerability.