CVE-2025-7187: code-projects Chat System fetch_member.php sql injection
Published Jul 8, 2025
·Updated
A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetchmember.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Chat System
Fabian Chat System=1.0
Event History
Jul 8, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 11, 58473
Event
via NVD·06:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7187?
CVE-2025-7187 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-7187?
CVE-2025-7187 is a SQL injection vulnerability.
3
Where is the CVE-2025-7187 vulnerability located?
CVE-2025-7187 is found in the file /user/fetch_member.php of the affected application.
4
How can I exploit CVE-2025-7187?
CVE-2025-7187 can be exploited remotely by manipulating the argument ID.
5
How do I fix CVE-2025-7187?
To fix CVE-2025-7187, ensure that all user inputs are properly sanitized and parameterized queries are implemented.