phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by crafting malicious payloads in the username field.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by crafting malicious payloads in the username field. | |
| Title | phpMyChat Plus 1.98 'deluser.php' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-05T15:38:23.460Z
Reserved: 2026-02-03T16:27:45.309Z
Link: CVE-2020-37151
Updated: 2026-02-05T15:38:16.730Z
Status : Awaiting Analysis
Published: 2026-02-05T16:15:48.657
Modified: 2026-02-05T16:29:43.907
Link: CVE-2020-37151
No data.
OpenCVE Enrichment
No data.