CVE-2025-9052 | projectworlds Travel Management System 1.0 /updatepackage.php s1 sql injection
A vulnerability was found in projectworlds Travel Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /updatepackage.php. Such manipulation of the argument s1 leads to sql injection.
This vulnerability is referenced as CVE-2025-9052. It is possible to launch the attack remotely. Furthermore, an exploit is available.