Metrics
Affected Vendors & Products
Thu, 02 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:foxcms:foxcms:*:*:*:*:*:*:*:* |
Fri, 12 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxcms
Foxcms foxcms |
|
| Vendors & Products |
Foxcms
Foxcms foxcms |
Thu, 11 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the argument ids results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | FoxCMS Images.php batchCope sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-11T13:33:52.704Z
Reserved: 2025-09-11T05:21:42.641Z
Link: CVE-2025-10251
Updated: 2025-09-11T13:33:41.955Z
Status : Analyzed
Published: 2025-09-11T13:15:53.577
Modified: 2025-10-02T19:38:41.853
Link: CVE-2025-10251
No data.