PT-2024-19632 · Projectworlds · Projectworlds Visitor Management System

·

CVE-2024-22983

·

Published

2024-02-28

·

Updated

2026-07-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Projectworlds Visitor Management System version 1.0
Description A SQL injection issue allows a remote attacker to escalate privileges via the name parameter in the "myform.php" endpoint. This enables the attacker to potentially gain unauthorized access to sensitive data or systems.
Recommendations For Projectworlds Visitor Management System version 1.0, consider disabling the myform.php endpoint or restricting access to it until a patch is available. Avoid using the name parameter in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22983

Affected Products

Projectworlds Visitor Management System