CVE-2025-9047: projectworlds Visitor Management System visitor_out.php sql injection
A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /visitorout.php. The manipulation of the argument rid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9047?
CVE-2025-9047 is a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-9047?
To fix CVE-2025-9047, ensure proper input validation and parameterized queries in the /visitor_out.php file.
Who is affected by CVE-2025-9047?
The CVE-2025-9047 vulnerability affects users of the Projectworlds Visitor Management System version 1.0.
What kind of attack can be performed using CVE-2025-9047?
An attacker can perform a remote SQL injection attack through the manipulation of the 'rid' parameter.
Is CVE-2025-9047 publicly disclosed?
Yes, CVE-2025-9047 has been publicly disclosed, allowing attackers to exploit the vulnerability.