CVE-2025-8471: projectworlds Online Admission System adminlogin.php sql injection
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument aid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8471?
CVE-2025-8471 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How does CVE-2025-8471 affect the Online Admission System?
CVE-2025-8471 specifically affects the file /adminlogin.php, where improper handling of the a_id argument can lead to SQL injection.
How can I mitigate the risk from CVE-2025-8471?
To mitigate CVE-2025-8471, sanitize and validate all user inputs, especially those passed to SQL queries.
Is CVE-2025-8471 exploitable remotely?
Yes, CVE-2025-8471 can be exploited remotely, allowing attackers to execute SQL injection attacks without physical access.
What versions of the Online Admission System are affected by CVE-2025-8471?
CVE-2025-8471 affects version 1.0 of the Projectworlds Online Admission System.