CVE-2018-25382: Bylancer Zechat
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database.
Affected products
- Bylancer Zechat: version 1.5 only
Published 2026-05-29. Last modified 2026-07-21.