A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.
References
Link | Resource |
---|---|
https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589d27ef8e1b9ebd86?source=copy_link | Exploit Third Party Advisory |
Configurations
History
09 Sep 2025, 19:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Foxcms foxcms
Foxcms |
|
CPE | cpe:2.3:a:foxcms:foxcms:1.2.6:*:*:*:*:*:*:* | |
References | () https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589d27ef8e1b9ebd86?source=copy_link - Exploit, Third Party Advisory |
22 Aug 2025, 18:09
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-21 16:15
Updated : 2025-09-09 19:12
NVD link : CVE-2025-55420
Mitre link : CVE-2025-55420
CVE.ORG link : CVE-2025-55420
JSON object : View
Products Affected
foxcms
- foxcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')