PT-2025-6877 · Fastcms · Fastcms

Ibkj1W

·

Published

2025-02-16

·

Updated

2025-02-16

·

CVE-2025-1332

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FastCMS versions up to 0.1.5
Description: A vulnerability has been found in the Template Menu component of FastCMS, affecting unknown code of the file /fastcms.html#/template/menu. The manipulation leads to cross-site scripting. The attack can be initiated remotely.
Recommendations: For FastCMS versions up to 0.1.5, consider disabling access to the /fastcms.html#/template/menu file until a fix is available. Restrict the use of the Template Menu component to minimize the risk of exploitation. Avoid using the Template Menu component in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-1332

Affected Products

Fastcms