CVE-2025-10667: itsourcecode Online Discussion Forum compose_msg.php sql injection
A weakness has been identified in itsourcecode Online Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /members/composemsg.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10667?
CVE-2025-10667 has been classified with a medium severity due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-10667?
To fix CVE-2025-10667, ensure input validation and parameterized queries are implemented to prevent SQL injection in the affected file /members/compose_msg.php.
Who is affected by CVE-2025-10667?
CVE-2025-10667 affects users of itsourcecode Online Discussion Forum version 1.0.
Can the CVE-2025-10667 vulnerability be exploited remotely?
Yes, the CVE-2025-10667 vulnerability can be exploited remotely by attacking the web application.
What type of vulnerability is CVE-2025-10667?
CVE-2025-10667 is an SQL injection vulnerability due to inappropriate handling of input in the application.