CVE-2026-6160

MEDIUM

code-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosure

Title source: cna

Description

A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-538
Status published
Products (1)
code-projects/Simple ChatBox 1.0
Published Apr 13, 2026
Tracked Since Apr 13, 2026