CVE-2025-3171
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 8, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-3171 is a critical vulnerability identified in the Project Worlds Online Lawyer Management System 1.0. This issue lies within the unknown code of the file /approve_lawyer.php, allowing an attacker to manipulate the unblock_id argument and execute SQL injection attacks. The exploit can be initiated remotely, meaning potential attackers don't need to have local access to the system to exploit it. The vulnerability has been disclosed to the public, increasing the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.