PT-2025-10034 · Unknown · Projectworlds Life Insurance Management System

Wuyadada

·

Published

2025-03-07

·

Updated

2025-05-14

·

CVE-2025-2062

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions projectworlds Life Insurance Management System version 1.0
Description A critical vulnerability has been found in the projectworlds Life Insurance Management System. The issue is related to an unknown function of the file /clientStatus.php, where the manipulation of the client id argument leads to SQL injection. This allows for remote attacks. The exploit has been publicly disclosed and may be used.
Recommendations For projectworlds Life Insurance Management System version 1.0, consider disabling the vulnerable function in /clientStatus.php until a patch is available. Restrict access to the client id argument in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-2062

Affected Products

Projectworlds Life Insurance Management System