A vulnerability marked as critical has been reported in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection.

This vulnerability is traded as CVE-2026-5672. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.