CVE-2025-10668: itsourcecode Online Discussion Forum compose_msg_admin.php sql injection
A security vulnerability has been detected in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file /members/composemsgadmin.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10668?
CVE-2025-10668 is rated as a critical vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-10668?
To fix CVE-2025-10668, update the itsourcecode Online Discussion Forum software to the latest version that addresses this SQL injection vulnerability.
What are the consequences of exploiting CVE-2025-10668?
Exploitation of CVE-2025-10668 can lead to unauthorized access to the database and manipulation of sensitive data.
Is CVE-2025-10668 remotely exploitable?
Yes, CVE-2025-10668 can be exploited remotely, allowing attackers to execute SQL injection attacks from outside the affected system.
Which version of itsourcecode Online Discussion Forum is affected by CVE-2025-10668?
CVE-2025-10668 affects version 1.0 of the itsourcecode Online Discussion Forum software.