A vulnerability marked as critical has been reported in Sourceforge 202CMS 10 beta. This impacts an unknown function of the component Requests Handler. The manipulation of the argument log_user leads to sql injection.
This vulnerability is documented as CVE-2019-25538. The attack can be initiated remotely. Additionally, an exploit exists.