A vulnerability classified as critical was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The manipulation of the argument user_Id results in sql injection.

This vulnerability was named CVE-2026-5985. The attack may be performed from remote. In addition, an exploit is available.