CVE-2025-9925: projectworlds Travel Management System detail.php sql injection
A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of the file /detail.php. The manipulation of the argument pid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9925?
CVE-2025-9925 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How does CVE-2025-9925 exploit occur?
CVE-2025-9925 exploits occur through manipulation of the 'pid' argument in the /detail.php file of the Travel Management System.
What systems are affected by CVE-2025-9925?
CVE-2025-9925 affects version 1.0 of the Projectworlds Travel Management System.
How do I fix CVE-2025-9925?
To fix CVE-2025-9925, validate and sanitize user inputs in the /detail.php file to prevent SQL injection.
Is CVE-2025-9925 publicly known?
Yes, CVE-2025-9925 has been made public and is known within the cybersecurity community.