PT-2026-31859 · Unknown · Simple It Discussion Forum

Zulu

·

Published

2026-04-10

·

Updated

2026-04-11

·

CVE-2026-6004

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple IT Discussion Forum version 1.0
Description A SQL injection flaw exists in the /delete-category.php file of Simple IT Discussion Forum version 1.0. Manipulation of the cat id argument can trigger the injection. The attack can be initiated remotely. The exploit is publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /delete-category.php file.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6004

Affected Products

Simple It Discussion Forum