Metrics
Affected Vendors & Products
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Projectworlds Projectworlds student Project Allocation System | |
| CPEs | cpe:2.3:a:projectworlds:student_project_allocation_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products | Projectworlds Projectworlds student Project Allocation System | 
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 17 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability classified as critical has been found in projectworlds Student Project Allocation System 1.0. This affects an unknown part of the file /make_group_sql.php. The manipulation of the argument mem1/mem2/mem3 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | projectworlds Student Project Allocation System make_group_sql.php sql injection | |
| Weaknesses | CWE-74 CWE-89 | |
| References |  | |
| Metrics | cvssV2_0 
 
 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-19T14:35:56.998Z
Reserved: 2025-05-16T14:28:05.744Z
Link: CVE-2025-4837
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-05-19T14:35:46.692Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-05-17T21:15:46.937
Modified: 2025-05-28T13:58:35.157
Link: CVE-2025-4837
 Redhat
                        Redhat
                    No data.