A vulnerability was found in spider312 MOGG Web Simulator Script. It has been declared as critical. The affected element is an unknown function of the file play.php. Executing a manipulation of the argument ID can lead to sql injection.

This vulnerability is registered as CVE-2018-25422. It is possible to launch the attack remotely. Furthermore, an exploit is available.