my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
History

Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared My Little Forum
My Little Forum my Little Forum
Vendors & Products My Little Forum
My Little Forum my Little Forum

Wed, 22 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Description my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Title my little forum vulnerable to SQL Injection in Bookmark Reordering via bookmarks parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-22T15:11:16.114Z

Updated: 2025-10-22T17:21:38.838Z

Reserved: 2025-10-16T19:24:37.268Z

Link: CVE-2025-62606

cve-icon Vulnrichment

Updated: 2025-10-22T17:21:25.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-22T15:16:07.493

Modified: 2025-10-22T21:12:32.330

Link: CVE-2025-62606

cve-icon Redhat

No data.