CVE-2025-9926: projectworlds Travel Management System viewsubcategory.php sql injection
A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9926?
CVE-2025-9926 is classified as a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-9926?
To fix CVE-2025-9926, you should sanitize and validate all user inputs, particularly the t1 argument in /viewsubcategory.php.
Who is affected by CVE-2025-9926?
CVE-2025-9926 affects users of Projectworlds Travel Management System version 1.0.
Can CVE-2025-9926 be exploited remotely?
Yes, CVE-2025-9926 can be exploited remotely, allowing attackers to perform SQL injection attacks.
What component of the Travel Management System is vulnerable in CVE-2025-9926?
The vulnerable component of the Travel Management System in CVE-2025-9926 is the /viewsubcategory.php file, specifically the t1 parameter.