vendor:
Fast PHP Chat
by:
Fatih Coskun
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Fast PHP Chat
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: YES
Related CWE: N/A
CPE: a:codecanyon:fast_php_chat:1.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2021
Fast PHP Chat 1.3 – ‘my_item_search’ SQL Injection
The vulnerability allows an attacker to inject sql commands from search section with 'my_item_search' parameter.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.