First published: Fri Mar 07 2025(Updated: )
A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Life Insurance Management System | ||
Life Insurance Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2064 is classified as a critical vulnerability.
CVE-2025-2064 affects the deletion functionality in the /deletePayment.php file, leading to a SQL injection vulnerability.
The primary risk of CVE-2025-2064 is unauthorized access to the database through SQL injection attacks.
Mitigation for CVE-2025-2064 includes sanitizing user inputs and implementing proper parameterized queries.
As of now, there is no specific patch available for CVE-2025-2064, but users should check for updates from the vendor.