CVE-2025-3176: Project Worlds Online Lawyer Management System single_lawyer.php sql injection
Published Apr 3, 2025
·Updated
A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /singlelawyer.php. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Project Worlds Online Lawyer Management System
Yugesh Verma Online Lawyer Management System=1.0
Event History
Apr 3, 2025
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Oct 29, 57230
Event
via FIRST·06:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-3176?
CVE-2025-3176 has been classified as a critical vulnerability.
2
What component of Project Worlds Online Lawyer Management System is affected by CVE-2025-3176?
CVE-2025-3176 affects the file /single_lawyer.php.
3
What type of vulnerability is CVE-2025-3176?
CVE-2025-3176 is classified as a SQL injection vulnerability.
4
Can CVE-2025-3176 be exploited remotely?
Yes, CVE-2025-3176 can be exploited remotely.
5
How do I fix CVE-2025-3176?
To fix CVE-2025-3176, ensure proper input validation and parameterized queries are implemented in the affected code.