CVE-2025-6866: code-projects Simple Forum forum_downloadfile.php path traversal
A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forumdownloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6866?
CVE-2025-6866 is classified as a critical vulnerability.
How does CVE-2025-6866 affect Simple Forum?
CVE-2025-6866 affects the /forum_downloadfile.php file, allowing path traversal through manipulation of the filename argument.
Can CVE-2025-6866 be exploited remotely?
Yes, CVE-2025-6866 can be exploited remotely by attackers.
What are the potential consequences of exploiting CVE-2025-6866?
Exploiting CVE-2025-6866 may allow unauthorized access to files on the server.
How do I patch CVE-2025-6866 in Simple Forum?
To patch CVE-2025-6866, you should review and secure the filename parameter in the /forum_downloadfile.php file to prevent path traversal.