CVE-2025-8948: projectworlds Visitor Management System front.php sql injection
A vulnerability was determined in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /front.php. The manipulation of the argument rid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8948?
CVE-2025-8948 is classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-8948?
To fix CVE-2025-8948, ensure to sanitize and validate user inputs in the /front.php file to prevent SQL injection attacks.
What type of vulnerability is CVE-2025-8948?
CVE-2025-8948 is identified as an SQL injection vulnerability affecting the Projectworlds Visitor Management System.
Is CVE-2025-8948 exploitable remotely?
Yes, CVE-2025-8948 can be exploited remotely, allowing attackers to manipulate the argument rid.
What software is affected by CVE-2025-8948?
CVE-2025-8948 affects the Projectworlds Visitor Management System version 1.0.