PT-2025-13394 · Foxcms · Foxcms

Somatrasss

·

Published

2025-03-27

·

Updated

2026-01-07

·

CVE-2025-29306

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FoxCMS version 1.2.5
Description An issue in FoxCMS allows a remote attacker to execute arbitrary code via the case display page in the index.html component. The vulnerability is related to a remote code execution issue.
Recommendations For FoxCMS version 1.2.5, as a temporary workaround, consider disabling the index.html component until a patch is available. Restrict access to the case display page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00114
CVE-2025-29306

Affected Products

Foxcms