FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
References
| Link | Resource |
|---|---|
| http://foxcms.com | Not Applicable |
| https://github.com/Ka7arotto/FoxCMS/blob/main/FoxCMS-rce3.md | Exploit |
| https://www.foxcms.cn/ | Product |
| https://github.com/Ka7arotto/FoxCMS/blob/main/FoxCMS-rce3.md | Exploit |
Configurations
History
No history.
Information
Published : 2025-02-26 15:15
Updated : 2025-04-09 14:08
NVD link : CVE-2025-25789
Mitre link : CVE-2025-25789
CVE.ORG link : CVE-2025-25789
JSON object : View
Products Affected
foxcms
- foxcms
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
