CVE-2025-55420

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.
Configurations

No configuration.

History

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad de Cross Site Scripting (XSS) reflejado en /index.php de FoxCMS v1.2.6. Cuando se envía un script manipulado mediante una solicitud GET, se refleja sin sanear en la respuesta HTML. Esto permite la ejecución de código JavaScript arbitrario cuando un usuario conectado envía la entrada maliciosa.

21 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 16:15

Updated : 2025-08-22 18:09


NVD link : CVE-2025-55420

Mitre link : CVE-2025-55420

CVE.ORG link : CVE-2025-55420


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')