CVE-2025-6849: code-projects Simple Forum forum_edit1.php cross site scripting
A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forumedit1.php. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6849?
CVE-2025-6849 is classified as problematic due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-6849?
To fix CVE-2025-6849, you should sanitize and validate user input in the affected function of /forum_edit1.php.
What software is affected by CVE-2025-6849?
CVE-2025-6849 affects version 1.0 of the Code-projects Simple Forum software.
Can CVE-2025-6849 be exploited remotely?
Yes, CVE-2025-6849 can be exploited remotely by manipulating the argument in the affected script.
What kind of attack is associated with CVE-2025-6849?
CVE-2025-6849 is associated with cross-site scripting (XSS) attacks.