SQL Injection Vulnerability in SourceCodester Simple Forum Discussion System
CVE-2025-10100
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 8 September 2025
Badges
What is CVE-2025-10100?
A vulnerability in SourceCodester's Simple Forum Discussion System 1.0 has been identified, allowing attackers to exploit the system via an SQL injection in the /admin_class.php?action=login function. By manipulating the argument Username, an unauthorized user can execute arbitrary SQL commands. The attack can be performed remotely, posing a significant risk as the exploit code has been made public, enabling potential attacks on unpatched systems.
Affected Version(s)
Simple Forum Discussion System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved