6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /visitor_out.php. The manipulation of the argument rid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-9047
Source
VulDB
Published
Aug 15, 2025 at 11:02
Affected Product
Vendor
projectworlds
Product
Visitor Management System
Version
1.0
Affected Versions
projectworlds Visitor Management System 1.0