SQL Injection Vulnerability in Projectworlds Visitor Management System
CVE-2025-8947
Key Information:
- Vendor
Projectworlds
- Vendor
- CVE Published:
- 14 August 2025
Badges
What is CVE-2025-8947?
An identified vulnerability exists within the Projectworlds Visitor Management System version 1.0. Specifically, the flaw involves improper handling in the /query_data.php file, allowing attackers to manipulate parameters dateF and dateP. This can result in SQL injection, enabling remote adversaries to execute unauthorized SQL commands, potentially exposing sensitive data. The issue has been made publicly known, increasing its risk for exploitation.
Affected Version(s)
Visitor Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved