A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. It has been declared as problematic. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting.

This vulnerability is listed as CVE-2026-6003. The attack may be performed from remote. In addition, an exploit is available.