Cyber Posture

CVE-2025-2065

HighPublic PoC

Published: 07 March 2025

Published
07 March 2025
Modified
14 May 2025
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0007 21.6th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may leverage databases to mine valuable information.

Security Summary

CVE-2025-2065 is a critical SQL injection vulnerability in projectworlds Life Insurance Management System version 1.0, affecting an unknown functionality within the /editAgent.php file. The issue arises from improper handling of the agent_id parameter, classified under CWE-74 and CWE-89. It carries a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), enabling remote exploitation without authentication or user interaction.

Attackers can exploit this vulnerability remotely by manipulating the agent_id parameter in requests to /editAgent.php, potentially leading to unauthorized access, data manipulation, or disruption with low impacts on confidentiality, integrity, and availability. No privileges are required, making it accessible to any unauthenticated remote actor.

Advisories and details are documented in references including a GitHub issue at https://github.com/ubfbuz3/cve/issues/7 and VulDB entries at https://vuldb.com/?ctiid.298821, https://vuldb.com/?id.298821, and https://vuldb.com/?submit.514758. The exploit has been publicly disclosed and may be actively used. No specific patch or mitigation steps are detailed in the available information.

Details

CWE(s)
CWE-74CWE-89

Affected Products

projectworlds
life insurance management system
1.0

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1213.006 Databases Collection
Adversaries may leverage databases to mine valuable information.
Why these techniques?

SQL injection in unauthenticated public-facing /editAgent.php enables exploitation of public-facing application (T1190) and data collection from backend databases via arbitrary queries (T1213.006).

References