A vulnerability described as critical has been identified in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argument msg can lead to sql injection.
This vulnerability is registered as CVE-2026-6161. It is possible to launch the attack remotely. Furthermore, an exploit is available.