CVE-2025-3172: Project Worlds Online Lawyer Management System lawyer_booking.php sql injection
A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyerbooking.php. The manipulation of the argument unblockid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3172?
CVE-2025-3172 is classified as a critical vulnerability due to its potential for SQL injection.
How does CVE-2025-3172 affect the Lawyer Management System?
CVE-2025-3172 specifically affects the processing of the argument unblock_id in the file /lawyer_booking.php.
What type of vulnerability is CVE-2025-3172?
CVE-2025-3172 is an SQL injection vulnerability, which allows attackers to manipulate database queries.
Can CVE-2025-3172 be exploited remotely?
Yes, CVE-2025-3172 can be exploited remotely if the affected system is accessible over the internet.
What are the potential consequences of CVE-2025-3172?
Exploitation of CVE-2025-3172 may lead to unauthorized access to sensitive data or complete system compromise.