Junglewise Threat Intelligence

CVE-2026-5672: code-projects Simple IT Discussion Forum SQL injection in edit-category.php

CVE-2026-5672 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: Code-Projects Simple IT Discussion Forum. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Simple IT Discussion Forum, a web application used for hosting online community discussions. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive user information or the modification of forum content. This attack can be carried out remotely without requiring any login credentials, posing a significant risk to the integrity and confidentiality of the platform.

Technical details

A SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 within the 'Parameter Handler' component of the /edit-category.php file. The root cause is the failure to sanitize or validate the 'cat_id' GET parameter before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted SQL payloads (including boolean-based blind, time-based blind, and UNION-based techniques). Successful exploitation allows for unauthorized database access, data exfiltration, and potential administrative takeover. A public exploit (PoC) has been disclosed.

Affected products

  • code-projects Simple IT Discussion Forum 1.0

Timeline

  • 2026-03-29: disclosed: Initial disclosure on GitHub issues
  • 2026-04-06: advisory: NVD/VulDB publication date

References

Related threats