First published: Fri Mar 21 2025(Updated: )
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation of the argument subject/message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor does not declare this issue a security vulnerability due to authentication requirements before being able to access any feature in the software that allows file modification.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Machines Forum (SMF) | ||
Simple Machines Forum | =2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2583 has been classified as problematic due to its potential for cross-site scripting attacks.
To fix CVE-2025-2583, you should update SimpleMachines SMF to the latest version provided by the vendor.
CVE-2025-2583 can facilitate remote cross-site scripting attacks through vulnerabilities in the ManageNews.php file.
Users of SimpleMachines SMF version 2.1.4 are affected by CVE-2025-2583.
Yes, there are known exploits that leverage CVE-2025-2583 to execute cross-site scripting attacks remotely.