CVE-2025-4034: projectworlds Online Examination System inser_doc_process.php sql injection
Published Apr 28, 2025
·Updated
A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /inserdocprocess.php. The manipulation of the argument DocID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Projectworlds Online Examination System
Projectworlds Online Examination System=1.0
Event History
Apr 28, 2025
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4034?
CVE-2025-4034 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-4034?
CVE-2025-4034 is an SQL injection vulnerability.
3
Which file is affected by CVE-2025-4034?
The vulnerability affects the file /inser_doc_process.php.
4
How can an attacker exploit CVE-2025-4034?
An attacker can exploit CVE-2025-4034 by manipulating the Doc_ID argument.
5
How do I fix CVE-2025-4034?
To fix CVE-2025-4034, implement proper input validation and prepared statements.