CVE Details
Basic Information
| Title | code-projects Public Chat Room send_message.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-07-25T18:02:06.168Z |
| Modified | 2025-07-25T18:24:17.352Z |
Product Information
| Vendor | code-projects |
|---|---|
| Product | Public Chat Room |
| Version | 1.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A SQL injection vulnerability in the send_message.php file of code-projects Public Chat Room 1.0 allows remote attackers to inject arbitrary SQL commands by manipulating the ID argument. This vulnerability is considered critical as it can lead to unauthorized access and data manipulation. |
|---|---|
| AI Severity | Medium |
| AI Vendor | code-projects.org |
| AI Product | Public Chat Room |
| AI Version | 1.0 |
Affected Products
- code-projects Public Chat Room 1.0
Additional Information
| CWE List | CWE-89, CWE-74 |
|---|---|
| Source | VulDB |
Description
A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_message.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.