Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bylancer
Bylancer zechat |
|
| Vendors & Products |
Bylancer
Bylancer zechat |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names. | |
| Title | Zechat 1.5 SQL Injection via hashtag parameter | |
| First Time appeared |
Zechat Project
Zechat Project zechat |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:zechat_project:zechat:1.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Zechat Project
Zechat Project zechat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-17T12:11:41.616Z
Updated: 2026-05-17T12:11:41.616Z
Reserved: 2026-05-17T12:06:26.102Z
Link: CVE-2018-25338
No data.
Status : Received
Published: 2026-05-17T13:16:45.590
Modified: 2026-05-17T13:16:45.590
Link: CVE-2018-25338
No data.