PT-2025-37181 · Foxcms · Foxcms

Jhsec.Com

·

Published

2025-09-11

·

Updated

2025-09-11

·

CVE-2025-10251

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FoxCMS versions prior to 1.24
Description: A SQL injection issue exists in FoxCMS due to the manipulation of the ids argument within the batchCope function located in the /app/admin/controller/Images.php file. This allows for remote exploitation. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations: As a temporary workaround, consider restricting access to the /app/admin/controller/Images.php file to minimize the risk of exploitation. Avoid using the ids parameter in the batchCope function until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10251

Affected Products

Foxcms