Executive brief
A vulnerability exists in the Simple IT Discussion Forum, a web-based platform for hosting community discussions. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive user information or the deletion of forum content. This attack can be carried out remotely without requiring any login credentials.
Technical details
A SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 within the '/delete-category.php' file. The root cause is the failure to sanitize or validate the 'cat_id' GET parameter before using it in a database query. An unauthenticated remote attacker can provide a malicious payload (e.g., error-based or time-based blind SQLi) to manipulate SQL queries. This can lead to unauthorized database access, data exfiltration, or data modification. A public exploit (PoC) using sqlmap has been disclosed. No official patch is currently documented, but remediation involves using prepared statements and parameter binding.
Affected products
- code-projects Simple IT Discussion Forum 1.0
Timeline
- 2026-04-01: disclosed: Initial disclosure on GitHub by zzb1388
- 2026-04-09: advisory: NVD/VulDB advisory published