PT-2025-12400 · Simple Machines · Simplemachines Smf

Fewwords

·

Published

2025-03-21

·

Updated

2025-04-21

·

CVE-2025-2583

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SimpleMachines SMF version 2.1.4
Description A vulnerability was found in SimpleMachines SMF, affecting an unknown part of the file ManageNews.php. The manipulation of the subject/message argument leads to cross-site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Recommendations For SimpleMachines SMF version 2.1.4, consider disabling the manipulation of the subject/message argument in the ManageNews.php file until a patch is available. Restrict access to the ManageNews.php file to minimize the risk of exploitation. Avoid using the subject/message argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-2583

Affected Products

Simplemachines Smf