CVE-2025-5213: projectworlds Responsive E-Learning System delete_file.php sql injection
A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/deletefile.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5213?
CVE-2025-5213 has been declared as critical.
How can I mitigate CVE-2025-5213?
Mitigation for CVE-2025-5213 involves sanitizing inputs to the /admin/delete_file.php file to prevent SQL injection.
What systems are affected by CVE-2025-5213?
CVE-2025-5213 affects the Projectworlds Responsive E-Learning System version 1.0.
What type of vulnerability is CVE-2025-5213?
CVE-2025-5213 is a SQL injection vulnerability.
What function in Projectworlds is exploited by CVE-2025-5213?
The vulnerability is exploited through an unknown functionality of the /admin/delete_file.php file.