CVE-2025-14570: projectworlds Advanced Library Management System view_admin.php sql injection
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /viewadmin.php. This manipulation of the argument adminid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14570?
CVE-2025-14570 is classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized access to sensitive data.
How do I fix CVE-2025-14570?
To fix CVE-2025-14570, validate and sanitize user inputs, particularly the admin_id parameter in the /view_admin.php file to prevent SQL injection.
Can CVE-2025-14570 be exploited remotely?
Yes, CVE-2025-14570 can be exploited remotely, allowing an attacker to manipulate the admin_id parameter from an external source.
Which software is affected by CVE-2025-14570?
CVE-2025-14570 affects version 1.0 of the Projectworlds Advanced Library Management System.
What type of vulnerability is CVE-2025-14570?
CVE-2025-14570 is an SQL injection vulnerability that allows unauthorized manipulation of database queries.