PT-2025-39449 · Unknown · Mufen-Mker Php-Usermm

M0Ker

·

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10967

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MuFen-mker PHP-Usermm versions prior to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9
Description A SQL injection issue exists in the file /chkuser.php due to manipulation of the Username argument. This allows for remote attacks. The exploit is publicly available. The software uses a rolling release model, and specific version information for affected or updated releases is not available. The vendor was contacted but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10967

Affected Products

Mufen-Mker Php-Usermm