A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.
References
| Link | Resource |
|---|---|
| https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589d27ef8e1b9ebd86?source=copy_link | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-08-21 16:15
Updated : 2025-09-09 19:12
NVD link : CVE-2025-55420
Mitre link : CVE-2025-55420
CVE.ORG link : CVE-2025-55420
JSON object : View
Products Affected
foxcms
- foxcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
