CVE-2025-2065: projectworlds Life Insurance Management System editAgent.php sql injection
A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agentid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2065?
CVE-2025-2065 is classified as a critical vulnerability.
How does CVE-2025-2065 affect the system?
CVE-2025-2065 allows for SQL injection through the manipulation of the agent_id parameter in the /editAgent.php file.
Can CVE-2025-2065 be exploited remotely?
Yes, CVE-2025-2065 can be exploited remotely, allowing attackers to execute SQL commands.
What software is impacted by CVE-2025-2065?
CVE-2025-2065 affects the projectworlds Life Insurance Management System version 1.0.
How can I mitigate the risks of CVE-2025-2065?
To mitigate CVE-2025-2065, sanitize and validate input parameters to prevent SQL injection.