Description
A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Published: 2025-10-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Feb 2026 07:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:projectworlds:gate_pass_management_system:*:*:*:*:*:*:*:*

Mon, 20 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:projectworlds:gate_pass_management_system:1.0:*:*:*:*:*:*:*

Fri, 10 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds
Projectworlds gate Pass Management System
Vendors & Products Projectworlds
Projectworlds gate Pass Management System

Thu, 09 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Title projectworlds Gate Pass Management System add-pass.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Projectworlds Gate Pass Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-24T06:56:45.392Z

Reserved: 2025-10-09T12:11:28.609Z

Link: CVE-2025-11557

cve-icon Vulnrichment

Updated: 2025-10-10T14:16:44.446Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-09T21:15:35.160

Modified: 2026-04-29T01:00:01.613

Link: CVE-2025-11557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-10T11:17:43Z

Weaknesses