CNNVD-202602-849 Information

CNNVD ID

CNNVD-202602-849

CVE-2020-37151

  • CNNVD Published: 2026-02-05

Description (Chinese)

phpMyChat Plus是Ciprianmp个人开发者的一个聊天室系统。 phpMyChat Plus 1.98版本存在SQL注入漏洞,该漏洞源于deluser.php页面中pmc_username参数存在SQL注入,可能导致敏感数据库信息泄露。

Description (English)

phpMyChat Plus is a chat room system for Ciprianmp personal developers. The phpMyChat Plus 1.98 version contains an injection loophole in SQL, which originates from the presence of the pmc username parameter in the deluser.php page and may lead to the leaking of sensitive database information.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

个人开发者

Published

2026-02-05

Last Modified

2026-02-24

References

http://ciprianmp.com/latest/ https://www.exploit-db.com/exploits/48066 https://www.vulncheck.com/advisories/phpmychat-plus-deluserphp-sql-injection

Share on: