CVE-2025-5003: projectworlds Online Time Table Generator semester_ajax.php sql injection
A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semesterajax.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5003?
CVE-2025-5003 has been classified as critical.
How does CVE-2025-5003 affect Online Time Table Generator?
CVE-2025-5003 affects the file /semester_ajax.php through SQL injection vulnerabilities.
Can CVE-2025-5003 be exploited remotely?
Yes, CVE-2025-5003 can be exploited remotely by manipulating the argument ID.
What are the potential consequences of exploiting CVE-2025-5003?
Exploiting CVE-2025-5003 can lead to unauthorized access to the database and sensitive data leakage.
How can I fix CVE-2025-5003?
To fix CVE-2025-5003, it is recommended to sanitize user inputs and implement prepared statements for database queries.