juzidddd/Projectworlds-ALMS-SQLi-Vulnerability-Disclosure

juzidddd/Projectworlds-ALMS-SQLi-Vulnerability-Disclosure

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such manipulation of the argument keywords leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.