CVE-2024-22922
Critical · CVSS 9.8Projectworlds Visitor Management System in PHP — Privilege Escalation via crafted login script (Improper Privilege Management)
- CVSS
- 9.8
- nvd
- EPSS
- 0.97%
- 58th pct
- KEV
- No
- Class
- other
- CWE-269, CWE-269
Description
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
Search profile — drives PoC discovery
Symbols index.phpPOST/index.phplogin pageCVE-2024-22922
Keywords CVE-2024-22922ProjectworldsVisitor Management SystemPHPprivilege escalationlogin bypassindex.phpcrafted scriptCWE-269
Versions: v1.0
Ranked PoCs (3) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 139Don-No7/Hack-SQL needs reviewgh_search
- ★ 0pwnpwnpur1n/CVE-2024-22922 needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z