PT-2024-19632 · Projectworlds · Projectworlds Visitor Management System

Keru6K

·

Published

2024-02-28

·

Updated

2025-05-02

·

CVE-2024-22983

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Projectworlds Visitor Management System version 1.0
Description A SQL injection issue allows a remote attacker to escalate privileges via the name parameter in the "myform.php" endpoint. This enables the attacker to potentially gain unauthorized access to sensitive data or systems.
Recommendations For Projectworlds Visitor Management System version 1.0, consider disabling the myform.php endpoint or restricting access to it until a patch is available. Avoid using the name parameter in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-22983

Affected Products

Projectworlds Visitor Management System