CVE-2026-6004: code-projects Simple IT Discussion Forum delete-category.php sql injection
A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument catid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6004?
CVE-2026-6004 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-6004?
To fix CVE-2026-6004, validate and sanitize the input parameters in the delete-category.php file.
What software is affected by CVE-2026-6004?
CVE-2026-6004 affects Code-Projects Simple IT Discussion Forum version 1.0.
What type of vulnerability is CVE-2026-6004?
CVE-2026-6004 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2026-6004 be exploited remotely?
Yes, CVE-2026-6004 can be exploited remotely if an attacker has access to the application's input parameters.