CVE-2025-10100: SourceCodester Simple Forum Discussion System admin_class.php sql injection
A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /adminclass.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10100?
CVE-2025-10100 has been rated as a serious vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-10100?
To fix CVE-2025-10100, ensure input validation and parameterized queries are implemented in the login action of the /admin_class.php file.
Who is affected by CVE-2025-10100?
CVE-2025-10100 affects users of SourceCodester Simple Forum Discussion System version 1.0.
What is the attack vector for CVE-2025-10100?
The attack vector for CVE-2025-10100 is remote, allowing an attacker to exploit the vulnerability without physical access.
What kind of attack is possible with CVE-2025-10100?
CVE-2025-10100 allows for SQL injection attacks, which can exploit database vulnerabilities through the manipulation of the Username argument.