CVE-2025-0172: code-projects Chat System deleteroom.php sql injection
Published Jan 2, 2025
·Updated
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/deleteroom.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Chat System
Code-projects Chat System=1.0
Event History
Jan 2, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 27, 57234
Event
via NVD·05:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-0172?
CVE-2025-0172 is classified as a critical vulnerability.
2
How do I fix CVE-2025-0172?
To fix CVE-2025-0172, patch the application by updating to the latest version of the Chat System.
3
What type of vulnerability is CVE-2025-0172?
CVE-2025-0172 is an SQL injection vulnerability.
4
Can CVE-2025-0172 be exploited remotely?
Yes, CVE-2025-0172 can be exploited remotely through the affected script.
5
Which file is affected in CVE-2025-0172?
The affected file in CVE-2025-0172 is /admin/deleteroom.php.