CVE-2025-25878: SQL Injection
Published Feb 21, 2025
·Updated
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data.
Affected Software
2 affected components
itsourcecode Simple ChatBox<=1.0
Angeljudesuarez Simple Chatbox=1.0
Event History
Feb 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25878?
CVE-2025-25878 is considered a critical vulnerability due to its potential exploitation via SQL injection.
2
How do I fix CVE-2025-25878?
To fix CVE-2025-25878, you should update ITSourcecode Simple ChatBox to a version above 1.0 that addresses this vulnerability.
3
What type of data can be compromised by CVE-2025-25878?
CVE-2025-25878 allows attackers to obtain sensitive information from the database through SQL injection.
4
Which file in ITSourcecode Simple ChatBox is affected by CVE-2025-25878?
The vulnerability CVE-2025-25878 affects the /del.php file in ITSourcecode Simple ChatBox.
5
Can CVE-2025-25878 lead to unauthorized access?
Yes, CVE-2025-25878 can lead to unauthorized access to sensitive data stored in the database.