CVE-2025-29306

Published Mar 27, 2025

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-29306 is a vulnerability found in FoxCMS version 1.2.5. It allows a remote attacker to execute arbitrary code through the "case display page" located in the `index.html` component. Specifically, the vulnerability resides within the FoxCMS software. An unauthenticated, remote attacker can exploit this vulnerability to inject and execute arbitrary code on the system by accessing the case display page.

Description
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending
  1. CVE-2025-29306 – #Unauthenticated #Remote_Code_Execution in #FoxCMS v1.2.5 via #Unserialize_Injection https://t.co/G7esNGo2ZN https://t.co/OE9tidOb36

    @omvapt

    5 Jul 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Deep Dive: CVE-2025-29306 (RCE in FoxCMS via unserialize injection) ⚠️ CVSS 9.8 | EPSS 71.52% No auth. No patch. Just an id parameter passed to unserialize()—and suddenly you’re running system() on the server. Craft a serialized payload, drop it in a URL or curl command,

    @offsectraining

    3 Jul 2025

    3272 Impressions

    1 Retweet

    15 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2025-43859 2 - CVE-2025-31324 3 - CVE-2024-27876 4 - CVE-2025-32432 5 - CVE-2025-29306 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-29306 - FoxCMS Remote Code Execution Exploit. Remote code execution vulnerability in FoxCMS. This tool allows testing single targets or scanning multiple hosts in bulk. https://t.co/vaBIYfDP1u https://t.co/JCJnZvD06L

    @cyber_advising

    26 Apr 2025

    2998 Impressions

    25 Retweets

    62 Likes

    26 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2025-29306 - critical 🚨 FoxCMS v.1.2.5 - Remote Code Execution > An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the... 👾 https://t.co/W0rbTekYil @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    23 Apr 2025

    19 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. POC - CVE-2025-29306 FOXCMS / Code Execution Vulnerability https://t.co/exeNBVFZ9K

    @MatthewThomz

    17 Apr 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.