CVE-2025-14571: projectworlds Advanced Library Management System borrow_book.php sql injection
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowbook.php. Such manipulation of the argument rollnumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14571?
CVE-2025-14571 has been classified as a high severity vulnerability due to its potential to enable SQL injection attacks.
How do I fix CVE-2025-14571?
To fix CVE-2025-14571, ensure that input validation and parameterized queries are implemented in the /borrow_book.php file to prevent SQL injection.
Can CVE-2025-14571 be exploited remotely?
Yes, CVE-2025-14571 can be exploited remotely, allowing attackers to manipulate the roll_number argument.
What software is affected by CVE-2025-14571?
CVE-2025-14571 affects versions of the Advanced Library Management System 1.0 developed by Projectworlds.
What type of attack is associated with CVE-2025-14571?
CVE-2025-14571 is associated with SQL injection attacks, which can compromise the database security.