CVE-2025-45239

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qianfox:foxcms:2.0.6:*:*:*:*:*:*:*

History

12 Jun 2025, 17:34

Type Values Removed Values Added
CPE cpe:2.3:a:qianfox:foxcms:2.0.6:*:*:*:*:*:*:*
References () https://gist.github.com/chao112122/350e1af42ccea185206f8a8b9e4906e1 - () https://gist.github.com/chao112122/350e1af42ccea185206f8a8b9e4906e1 - Exploit, Third Party Advisory
References () https://gitee.com/qianfox/foxcms/tree/V1.2.5/ - () https://gitee.com/qianfox/foxcms/tree/V1.2.5/ - Release Notes
First Time Qianfox
Qianfox foxcms

13 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-22
Summary
  • (es) Un problema en el método de restauración (DataBackup.php) de foxcms v2.0.6 permite a los atacantes ejecutar un directory traversal.

05 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-05 18:15

Updated : 2025-06-12 17:34


NVD link : CVE-2025-45239

Mitre link : CVE-2025-45239

CVE.ORG link : CVE-2025-45239


JSON object : View

Products Affected

qianfox

  • foxcms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')