CVE-2025-55420

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.
Configurations

Configuration 1 (hide)

cpe:2.3:a:foxcms:foxcms:1.2.6:*:*:*:*:*:*:*

History

09 Sep 2025, 19:12

Type Values Removed Values Added
First Time Foxcms foxcms
Foxcms
CPE cpe:2.3:a:foxcms:foxcms:1.2.6:*:*:*:*:*:*:*
References () https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589d27ef8e1b9ebd86?source=copy_link - () https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589d27ef8e1b9ebd86?source=copy_link - Exploit, Third Party Advisory

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad de Cross Site Scripting (XSS) reflejado en /index.php de FoxCMS v1.2.6. Cuando se envía un script manipulado mediante una solicitud GET, se refleja sin sanear en la respuesta HTML. Esto permite la ejecución de código JavaScript arbitrario cuando un usuario conectado envía la entrada maliciosa.

21 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 16:15

Updated : 2025-09-09 19:12


NVD link : CVE-2025-55420

Mitre link : CVE-2025-55420

CVE.ORG link : CVE-2025-55420


JSON object : View

Products Affected

foxcms

  • foxcms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')