SQL Injection Vulnerability in Project Worlds Car Rental Application by Project Worlds
CVE-2025-4457
Key Information:
- Vendor
Project Worlds
- Status
- Vendor
- CVE Published:
- 9 May 2025
Badges
What is CVE-2025-4457?
A security vulnerability has been identified in the Project Worlds Car Rental Project version 1.0 that allows attackers to exploit an unknown functionality in the /admin/approve.php file. By manipulating the argument ID, attackers can execute SQL injection attacks remotely. This vulnerability has been publicly disclosed, making systems utilizing this software particularly susceptible to exploitation. Immediate action is recommended to mitigate potential risks.
Affected Version(s)
Car Rental Project 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved