CVE-2025-2062: projectworlds Life Insurance Management System clientStatus.php sql injection
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument clientid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2062?
CVE-2025-2062 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-2062?
CVE-2025-2062 is a SQL injection vulnerability affecting the Life Insurance Management System.
How is CVE-2025-2062 exploited?
CVE-2025-2062 can be exploited by manipulating the client_id argument in the /clientStatus.php file.
Who is affected by CVE-2025-2062?
CVE-2025-2062 affects users of projectworlds Life Insurance Management System version 1.0.
How do I fix CVE-2025-2062?
To fix CVE-2025-2062, validate and sanitize user inputs, specifically the client_id parameter, to prevent SQL injection.