A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing manipulation of the argument book_pub/book_title results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
History

Wed, 19 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:projectworlds:advanced_library_management_system:1.0:*:*:*:*:*:*:*

Mon, 17 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds
Projectworlds advanced Library Management System
Vendors & Products Projectworlds
Projectworlds advanced Library Management System

Mon, 17 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing manipulation of the argument book_pub/book_title results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Title projectworlds Advanced Library Management System book_search.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-17T00:32:06.284Z

Updated: 2025-11-17T18:37:53.164Z

Reserved: 2025-11-16T10:40:27.689Z

Link: CVE-2025-13255

cve-icon Vulnrichment

Updated: 2025-11-17T18:37:46.950Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-17T01:15:44.823

Modified: 2025-11-19T13:16:50.373

Link: CVE-2025-13255

cve-icon Redhat

No data.