phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.
References
Link Resource
https://github.com/J3rryBl4nks/PHPMyChatPlus/blob/master/SQLi.md Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-18T17:22:38

Updated: 2020-02-18T17:22:38

Reserved: 2020-02-18T00:00:00


Link: CVE-2020-9265

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-18T19:15:16.317

Modified: 2020-02-27T16:37:23.567


Link: CVE-2020-9265

JSON object: View

cve-icon Redhat Information

No data.

CWE