PT-2025-35219 · Unknown · Shafhasan Chatbox

Maloyroyorko

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-9651

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

shafhasan chatbox versions prior to 156a39cde62f78532c3265a70eda12c70907e56f

Description:

A vulnerability exists in shafhasan chatbox due to SQL injection. The issue is located in the `/chat.php` file and affects an unknown function. Manipulation of the `user id` argument can trigger the vulnerability. The attack can be performed remotely. The exploit has been made public.

Recommendations:

As a temporary workaround, consider restricting access to the `/chat.php` file until a fix is available.

Avoid using the `user id` parameter in the affected file until the issue is resolved.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9651

Affected Products

Shafhasan Chatbox