Executive brief
Simple IT Discussion Forum is a PHP-based application used to host online community discussions. A security flaw in the category management component allows an attacker to manipulate database queries without needing a password. This could lead to the theft of sensitive user information, unauthorized modification of forum content, or a complete shutdown of the service.
Technical details
A SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 within the '/add-category-function.php' file. The root cause is the failure to sanitize or validate the 'category' POST parameter before using it in a database query. An unauthenticated remote attacker can exploit this by sending specially crafted SQL payloads, such as time-based blind injection strings. Successful exploitation allows for unauthorized database access, data exfiltration, and potential administrative bypass. A public exploit (PoC) has been disclosed, and no official patch is currently available for this open-source project.
Affected products
- code-projects Simple IT Discussion Forum 1.0
Timeline
- 2026-04-02: disclosed: Public issue opened on GitHub with PoC details
- 2026-04-10: advisory: CVE-2026-6031 published