CVE-2025-4024
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-4024 is a newly discovered critical vulnerability in the Placement Management System 1.0. An unknown function within the file /add_drive.php is the culprit, allowing attackers to execute SQL injection through manipulation of the drive_title argument. This vulnerability permits remote exploitation, making it a significant threat. The exploit for this issue has been made public, increasing the risk of attacks. Further investigation suggests that other parameters may also be impacted.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.