CVE-2025-6844: code-projects Simple Forum signin.php sql injection
A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6844?
CVE-2025-6844 has been classified as a critical severity vulnerability.
What is the nature of the vulnerability in CVE-2025-6844?
CVE-2025-6844 involves a SQL injection vulnerability through the manipulation of the 'User' argument in the /signin.php file.
Can the CVE-2025-6844 vulnerability be exploited remotely?
Yes, the CVE-2025-6844 vulnerability can be exploited remotely.
How do I fix CVE-2025-6844?
To fix CVE-2025-6844, sanitize and validate inputs to prevent SQL injection vulnerabilities.
Which software is affected by CVE-2025-6844?
CVE-2025-6844 affects version 1.0 of the Code-projects Simple Forum application.