Vulnerability record · CVE-2025-29306 · published 27 March 2025
CVE-2025-29306: FoxCMS index.html case display page code injection
Foxcms · Foxcms
FoxCMS 1.2.5 contains a code injection flaw (CWE-94) reachable through the case display page in the index.html component, allowing a remote attacker to execute arbitrary code. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a severe pre-auth remote code execution risk for exposed installations.
Description
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a public exploit reference makes this a critical pre-auth RCE risk.
What it is
FoxCMS 1.2.5 contains a code injection flaw (CWE-94) reachable through the case display page in the index.html component, allowing a remote attacker to execute arbitrary code. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a severe pre-auth remote code execution risk for exposed installations.
Impact
An unauthenticated remote attacker can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability of the FoxCMS host and any data it serves.
Attack surface
Reached over the network via the case display page in the index.html component; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.46583 (98.8th percentile) and a public exploit reference exists on GitHub, indicating meaningful and elevated exploitation likelihood.
What to do
- Apply the vendor fix for FoxCMS 1.2.5 or upgrade to a patched release as soon as one is available; if no patch exists, restrict or disable the case display page.
- Place FoxCMS behind a WAF or reverse proxy with rules blocking code-injection patterns targeting the index.html case display endpoint.
- Remove or restrict public internet exposure of FoxCMS administrative and content pages until patched.
- Run the web service with least privilege and isolate it from sensitive internal systems to limit post-exploitation reach.
Detection
- Monitor web logs for suspicious requests to the index.html case display page containing code or template injection payloads.
- Alert on unexpected child processes spawned by the web server (e.g., shell, curl, wget) indicating code execution.
- Review file integrity on FoxCMS web directories for newly written or modified files after page requests.
- Correlate outbound network connections from the FoxCMS host with inbound requests to the vulnerable page.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/somatrasss/CVE-2025-29306 | ExploitThird Party Advisory |
Track CVE-2025-29306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-29306), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.