PT-2025-6877 · Fastcms · Fastcms
Ibkj1W
·
Published
2025-02-16
·
Updated
2025-02-16
·
CVE-2025-1332
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
FastCMS versions up to 0.1.5
Description:
A vulnerability has been found in the Template Menu component of FastCMS, affecting unknown code of the file /fastcms.html#/template/menu. The manipulation leads to cross-site scripting. The attack can be initiated remotely.
Recommendations:
For FastCMS versions up to 0.1.5, consider disabling access to the /fastcms.html#/template/menu file until a fix is available. Restrict the use of the Template Menu component to minimize the risk of exploitation. Avoid using the Template Menu component in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fastcms