CVE-2025-6848: code-projects Simple Forum forum1.php unrestricted upload
Published Jun 29, 2025
·Updated
A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Simple Forum
Fabian Simple Forum=1.0
Event History
Jun 29, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 9, 57515
Event
via FIRST·04:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6848?
CVE-2025-6848 is classified as a critical vulnerability.
2
How does CVE-2025-6848 affect the Simple Forum software?
CVE-2025-6848 affects the handling of the /forum1.php file, allowing for unrestricted file uploads.
3
Can CVE-2025-6848 be exploited remotely?
Yes, CVE-2025-6848 can be exploited remotely by an attacker.
4
What is a potential impact of exploiting CVE-2025-6848?
Exploitation of CVE-2025-6848 could lead to unauthorized access or control of the server.
5
How can I mitigate the risks associated with CVE-2025-6848?
To mitigate CVE-2025-6848, ensure that file upload functionalities are properly validated and restricted.