ZeroHour

CVE-2025-29306

PoC

Unauthenticated RCE in FoxCMS 1.2.5 via case display page

CVSS 3.1
9.8 critical
EPSS
47%p99
Published
()
Modified
AI analysis

CVE-2025-29306 is a code-injection flaw (CWE-94) in FoxCMS 1.2.5, an open-source content management system, that allows unauthenticated remote code execution through the case display page in the index.html component. A remote attacker needs no privileges and no user interaction (per the CVSS 3.1 vector) to reach the affected page and have the application execute attacker-controlled code on the web server, yielding full confidentiality, integrity, and availability impact (CVSS 9.8, critical). Any deployment running FoxCMS 1.2.5 is affected; the advisory cites only that version, so operators of other releases should confirm their exposure against the vendor's advisories. Exploitation is not yet confirmed in the wild and the issue is not in CISA's KEV, but a public proof-of-concept is available on GitHub and EPSS assigns a high 46.6% probability of exploitation within 30 days.

What to do: Upgrade FoxCMS to the newest release available from the vendor — no fixed version is specified in the available data, so confirm the patched version in the project's official release notes before deploying. Until patched, restrict external access to the case display functionality and review web server logs for anomalous requests to the index.html case page and indicators of code execution (unexpected processes, webshells). Given the elevated EPSS (46.6%), prioritize patching internet-facing instances.

Affected
foxcms1.2.5 (the only version explicitly cited in the CVE description; other versions are not specified in the available data)
Estimated exposure
unknown (niche, self-hosted open-source CMS; no public install counts or internet-exposure scan data) — The source data provides no active-install counts, download statistics, or public internet-exposure scans for FoxCMS, and its niche, self-hosted deployment pattern supports only a qualitative assessment, so the affected population cannot…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

Vendors
foxcms
Products
foxcms
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.