A vulnerability, which was classified as critical, was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection.
This vulnerability is cataloged as CVE-2026-5828. The attack may be launched remotely. Furthermore, there is an exploit available.