Authenticated SQL Injection Vulnerability in My Little Forum by My Little Forum
CVE-2025-62606
8.8HIGH
What is CVE-2025-62606?
My Little Forum, a PHP and MySQL based internet forum, prior to version 2.5.12, contains an authenticated SQL injection vulnerability within the bookmark reordering feature. This flaw allows any logged-in user to execute arbitrary SQL commands. As a result, it poses a serious risk to the application's database, enabling potential unauthorized access to read, modify, or delete all data. This critical issue has been addressed and patched in version 2.5.12.
Affected Version(s)
mylittleforum < 2.5.12