CVE-2025-9053: projectworlds Travel Management System updatesubcategory.php sql injection
A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9053?
CVE-2025-9053 is classified as a high severity vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2025-9053?
To fix CVE-2025-9053, you should sanitize all user inputs and implement prepared statements for database queries in the affected code.
What software is affected by CVE-2025-9053?
CVE-2025-9053 affects the Projectworlds Travel Management System version 1.0.
What type of attack is associated with CVE-2025-9053?
CVE-2025-9053 is associated with SQL injection attacks that can be exploited remotely.
Can CVE-2025-9053 be exploited without authentication?
Yes, CVE-2025-9053 can be exploited remotely without requiring user authentication.