6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /enquiry.php. The manipulation of the argument t2 leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-9924
Source
VulDB
Published
Sep 3, 2025 at 18:32
Modified
Sep 3, 2025 at 18:50
Affected Product
Vendor
projectworlds
Product
Travel Management System
Version
1.0
Affected Versions
projectworlds Travel Management System 1.0