my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Description my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Title my little forum vulnerable to SQL Injection in Bookmark Reordering via bookmarks parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-22T17:21:38.838Z

Reserved: 2025-10-16T19:24:37.268Z

Link: CVE-2025-62606

cve-icon Vulnrichment

Updated: 2025-10-22T17:21:25.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-22T15:16:07.493

Modified: 2025-10-22T21:12:32.330

Link: CVE-2025-62606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.