Meeplace Business Review Script SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Meeplace Business Review Script, allowing unauthenticated attackers to execute arbitrary SQL queries. The vulnerability arises from improper handling of the 'id' parameter in GET requests to the addclick.php endpoint. Exploitation of this vulnerability could lead to unauthorized access to sensitive database information or cause a denial-of-service condition.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, which could be used to manipulate database queries, extract sensitive information, or cause a denial-of-service condition by disrupting normal database operations.

Reproduction

To reproduce this vulnerability, send a GET request to the addclick.php endpoint with a crafted SQL payload in the 'id' parameter. The injected SQL code can be designed to extract database information or disrupt service by, for example, causing a delay in response.

Added: Mar 24, 2026, 12:29 PM
Updated: Mar 24, 2026, 12:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
4.6
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.