CVE-2025-9051: projectworlds Travel Management System updatecategory.php sql injection
A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /updatecategory.php. The manipulation of the argument t1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9051?
CVE-2025-9051 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-9051?
To fix CVE-2025-9051, validate and sanitize user inputs before processing SQL queries.
What are the potential impacts of exploiting CVE-2025-9051?
Exploiting CVE-2025-9051 can lead to unauthorized access to database information and manipulation.
Is CVE-2025-9051 remotely exploitable?
Yes, CVE-2025-9051 can be exploited remotely by manipulating the argument in the vulnerable endpoint.
Which software is affected by CVE-2025-9051?
CVE-2025-9051 affects version 1.0 of the Projectworlds Travel Management System.