Cyber Posture

CVE-2025-25876

HighPublic PoC

Published: 21 February 2025

Published
21 February 2025
Modified
28 March 2025
KEV Added
Patch
CVSS Score 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0008 23.8th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may leverage databases to mine valuable information.

Security Summary

CVE-2025-25876 is a SQL injection vulnerability (CWE-89) discovered in ITSourcecode Simple ChatBox versions up to 1.0. The issue resides in unknown code within the /delete.php file, enabling attackers to obtain sensitive data through malicious SQL queries.

The vulnerability has a CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating it is exploitable over the network with low complexity and no user interaction required, but necessitates high privileges (PR:H) such as authenticated administrative access. Attackers with sufficient permissions can achieve high impacts across confidentiality, integrity, and availability, potentially extracting sensitive data, modifying database contents, or disrupting services.

A proof-of-concept exploit is documented in the reference at https://github.com/SticKManII/cve-poc/blob/main/chat-box/2/poc.md. No vendor advisories, patches, or specific mitigation guidance are detailed in the available information.

Details

CWE(s)
CWE-89

Affected Products

angeljudesuarez
simple chatbox
1.0

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1213.006 Databases Collection
Adversaries may leverage databases to mine valuable information.
Why these techniques?

SQL injection in public-facing web application (/delete.php) enables exploitation of public-facing application (T1190) and collection of sensitive data from databases (T1213.006).

References