CVE-2025-3171

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 8, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-3171 is a critical vulnerability identified in the Project Worlds Online Lawyer Management System 1.0. This issue lies within the unknown code of the file /approve_lawyer.php, allowing an attacker to manipulate the unblock_id argument and execute SQL injection attacks. The exploit can be initiated remotely, meaning potential attackers don't need to have local access to the system to exploit it. The vulnerability has been disclosed to the public, increasing the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share