Description
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Published: 2025-10-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared My Little Forum
My Little Forum my Little Forum
Vendors & Products My Little Forum
My Little Forum my Little Forum

Wed, 22 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Description my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Title my little forum vulnerable to SQL Injection in Bookmark Reordering via bookmarks parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

My Little Forum My Little Forum
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-22T17:21:38.838Z

Reserved: 2025-10-16T19:24:37.268Z

Link: CVE-2025-62606

cve-icon Vulnrichment

Updated: 2025-10-22T17:21:25.738Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:16:07.493

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-23T09:58:53Z

Weaknesses