A vulnerability classified as critical was found in Bylancer Zechat 1.5 . Affected by this issue is some unknown functionality. Executing a manipulation of the argument hashtag can lead to sql injection. This vulnerability is registered as CVE-2018-25338 . It is possible to launch the attack remotely. Furthermore, an exploit is available.