CVE-2025-2063: projectworlds Life Insurance Management System deleteNominee.php sql injection
A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nomineeid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2063?
CVE-2025-2063 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-2063?
To fix CVE-2025-2063, you should validate and sanitize all inputs for the nominee_id parameter in the /deleteNominee.php file.
What type of vulnerability is CVE-2025-2063?
CVE-2025-2063 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Which software is affected by CVE-2025-2063?
CVE-2025-2063 affects the projectworlds Life Insurance Management System version 1.0.
What could an attacker achieve by exploiting CVE-2025-2063?
An attacker could exploit CVE-2025-2063 to gain unauthorized access to the database, allowing them to view, modify, or delete sensitive data.