CVE-2025-4457: Project Worlds Car Rental Project approve.php sql injection
A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4457?
CVE-2025-4457 is classified as a critical vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2025-4457?
To fix CVE-2025-4457, ensure that proper input validation and parameterized queries are implemented in the /admin/approve.php file.
What are the potential consequences of CVE-2025-4457?
The consequences of CVE-2025-4457 can include unauthorized access to sensitive data and database manipulation due to SQL injection.
Is CVE-2025-4457 easy to exploit?
Yes, CVE-2025-4457 can be exploited remotely with minimal technical skills using crafted SQL queries.
Which software is affected by CVE-2025-4457?
CVE-2025-4457 affects Project Worlds Car Rental Project version 1.0.