PT-2025-43365 · Unknown · My Little Forum

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-62606

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions my little forum versions prior to 2.5.12
Description my little forum is a PHP and MySQL based internet forum. A SQL injection issue exists in the bookmark reordering feature for authenticated users. This allows execution of arbitrary SQL commands, potentially leading to a full compromise of the application’s database, including the ability to read, modify, or delete all data.
Recommendations Update to version 2.5.12 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62606
GHSA-M8HJ-C6GR-6H6V

Affected Products

My Little Forum