CVE-2025-2582

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 21, 2025
Updated: Mar 24, 2025
CWE ID 79

Summary

CVE-2025-2582 is a newly disclosed vulnerability affecting SimpleMachines SMF 2.1.4. The issue lies within the ManageAttachments.php file and involves manipulation of the Notice argument. This vulnerability results in cross-site scripting, allowing attackers to inject malicious code into unsuspecting users' browsers. The exploit can be executed remotely, increasing the threat level. The vulnerability has been publicly disclosed, potentially enabling widespread exploitation. The vendor was notified early about this disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share