Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yf3Te

#30915of 53,624
8.4Total CVSS
Vulnerabilities · 1
PT-2025-23616
8.4
2025-06-03
Foxcms · Foxcms · CVE-2025-46154
**Name of the Vulnerable Software and Affected Versions** Foxcms version 1.25 **Description** The issue is related to a SQL time injection in the `installdb.php` script, specifically affecting the `$ POST['dbname']` parameter. This allows for potential exploitation. **Recommendations** For Foxcms version 1.25, consider restricting access to the `installdb.php` script until a patch is available. As a temporary workaround, avoid using the `dbname` parameter in the affected script to minimize the risk of exploitation.