CVE-2025-7189: code-projects Chat System send_message.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/sendmessage.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7189?
CVE-2025-7189 is classified as a critical severity vulnerability.
How does CVE-2025-7189 impact the Chat System?
CVE-2025-7189 allows for SQL injection through manipulated arguments in the /user/send_message.php file.
What is the potential consequence of exploiting CVE-2025-7189?
Exploitation of CVE-2025-7189 can lead to unauthorized access to the database and data leakage.
How can I mitigate CVE-2025-7189?
To mitigate CVE-2025-7189, sanitize and validate all inputs to prevent SQL injection attacks.
Is there a patch available for CVE-2025-7189?
Currently, there is no specific patch mentioned for CVE-2025-7189, but upgrading to the latest version of the Chat System is recommended.