A vulnerability classified as critical was found in EngineerCMS up to 2.0.5. Affected by this vulnerability is an unknown functionality of the file /project/addproject. The manipulation leads to sql injection.

This vulnerability is known as CVE-2025-44831. The attack can be launched remotely. There is no exploit available.