CVE-2025-4837: projectworlds Student Project Allocation System make_group_sql.php sql injection
A vulnerability classified as critical has been found in projectworlds Student Project Allocation System 1.0. This affects an unknown part of the file /makegroupsql.php. The manipulation of the argument mem1/mem2/mem3 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4837?
CVE-2025-4837 is classified as a critical vulnerability.
How do I fix CVE-2025-4837?
To fix CVE-2025-4837, sanitize and validate all user inputs to prevent SQL injection in the affected file /make_group_sql.php.
What kind of attack does CVE-2025-4837 facilitate?
CVE-2025-4837 facilitates SQL injection attacks through manipulation of the arguments mem1, mem2, and mem3.
What software is affected by CVE-2025-4837?
CVE-2025-4837 affects the Student Project Allocation System version 1.0 developed by projectworlds.
Is CVE-2025-4837 easy to exploit?
Yes, the vulnerability CVE-2025-4837 can be exploited easily if proper input validation is not implemented.