CVE-2018-25382

HIGH

Zechat 1.5 SQL Injection via uname Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25382. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This is a functional SQL injection exploit for Zechat 1.5, targeting the 'uname' parameter in profile.php. The payload uses UNION-based injection to extract table and column names from the information_schema database.

Description

Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45523

This is a functional SQL injection exploit for Zechat 1.5, targeting the 'uname' parameter in profile.php. The payload uses UNION-based injection to extract table and column names from the information_schema database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zechat 1.5
No auth needed
Prerequisites: access to the profile.php endpoint
devstral-2 · analyzed May 29, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-45523
https://www.exploit-db.com/exploits/45523
Product product
Official Product Homepage
https://bylancer.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Zechat 1.5 SQL Injection via uname Parameter
https://www.vulncheck.com/advisories/zechat-sql-injection-via-uname-parameter

Scores

CVSS v3 8.2
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Bylancer/Zechat 1.5
Published May 29, 2026
Tracked Since May 29, 2026