Back

HIGH

Zechat 1.5 SQL Injection via uname Parameter

Published May 29, 2026

Description

Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 29, 2026
Updated Jun 2, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Jun 2, 2026
NVD
Status Deferred
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a