PT-2026-31859 · Unknown · Simple It Discussion Forum
Zulu
·
Published
2026-04-10
·
Updated
2026-04-11
·
CVE-2026-6004
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple IT Discussion Forum version 1.0
Description
A SQL injection flaw exists in the /delete-category.php file of Simple IT Discussion Forum version 1.0. Manipulation of the
cat id argument can trigger the injection. The attack can be initiated remotely. The exploit is publicly available.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /delete-category.php file.
Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple It Discussion Forum