Chaitak-Gorai Blogbook SQL Injection Vulnerability in POST Parameter

Vulnerability

A critical SQL injection vulnerability has been identified in the Chaitak-Gorai Blogbook application, specifically in versions up to commit 92f5cf90f8a7e6566b576fe0952e14e1c6736513. The issue arises in the 'post.php' file, where user-supplied input from the 'p_id' GET parameter is improperly sanitized before being incorporated into SQL queries. This vulnerability allows remote, unauthenticated attackers to inject and execute arbitrary SQL commands, potentially leading to unauthorized access to, modification of, or further compromise of the database.

Impact

Exploitation of this vulnerability allows for arbitrary SQL injection, which could be used to manipulate database queries, access or modify database information, or execute administrative operations on the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.1
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.