CVE-2025-0967: code-projects Chat System add_chatroom.php sql injection
Published Feb 2, 2025
·Updated
A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/addchatroom.php. The manipulation of the argument chatname/chatpass leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Chat System
Fabian Chat System=1.0
Event History
Feb 2, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0967?
CVE-2025-0967 is classified as a critical vulnerability.
2
How does CVE-2025-0967 impact the Chat System?
CVE-2025-0967 allows an attacker to exploit SQL injection in the file /user/add_chatroom.php.
3
What conditions are required to exploit CVE-2025-0967?
CVE-2025-0967 can be exploited remotely without any prior authentication.
4
How do I fix CVE-2025-0967?
To fix CVE-2025-0967, validate and sanitize user inputs for the chatname and chatpass parameters.
5
What versions of the Chat System are affected by CVE-2025-0967?
CVE-2025-0967 affects code-projects Chat System version 1.0.