CVE-2025-4706 | projectworlds Online Examination System 1.0 Procedure3b_yearwiseVisit.php Visit_year sql injection
A vulnerability identified as critical has been detected in projectworlds Online Examination System 1.0. This affects an unknown part of the file /Procedure3b_yearwiseVisit.php. Performing manipulation of the argument Visit_year results in sql injection.
This vulnerability was named CVE-2025-4706. The attack may be initiated remotely. In addition, an exploit is available.