CVE-2025-4706: projectworlds Online Examination System Procedure3b_yearwiseVisit.php sql injection
A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Procedure3byearwiseVisit.php. The manipulation of the argument Visityear leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4706?
CVE-2025-4706 has been declared as critical due to its potential for SQL injection.
How do I fix CVE-2025-4706?
To fix CVE-2025-4706, sanitize and validate the input for the Visit_year parameter to prevent SQL injection.
What software is affected by CVE-2025-4706?
CVE-2025-4706 affects the projectworlds Online Examination System version 1.0.
What type of vulnerability is CVE-2025-4706?
CVE-2025-4706 is classified as an SQL injection vulnerability.
Can CVE-2025-4706 lead to data compromise?
Yes, exploiting CVE-2025-4706 can lead to unauthorized access and potential data compromise.