A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
History

Fri, 05 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:projectworlds:travel_management_system:1.0:*:*:*:*:*:*:*

Thu, 04 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds
Projectworlds travel Management System
Vendors & Products Projectworlds
Projectworlds travel Management System

Wed, 03 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Title projectworlds Travel Management System viewcategory.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-03T21:02:06.094Z

Updated: 2025-09-04T15:57:21.106Z

Reserved: 2025-09-03T11:22:17.805Z

Link: CVE-2025-9928

cve-icon Vulnrichment

Updated: 2025-09-04T15:57:17.039Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-03T21:15:34.357

Modified: 2025-09-05T16:39:50.020

Link: CVE-2025-9928

cve-icon Redhat

No data.