CVE-2025-12920
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
09/11/2025
Última modificación:
14/11/2025
Descripción
*** Pendiente de traducción *** A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impacto
Puntuación base 4.0
4.80
Gravedad 4.0
MEDIA
Puntuación base 3.x
2.40
Gravedad 3.x
BAJA
Puntuación base 2.0
3.30
Gravedad 2.0
BAJA
Referencias a soluciones, herramientas e información
- https://github.com/21151213732/CVE/blob/main/FoxCMS-XSS2.md
- https://github.com/21151213732/CVE/blob/main/FoxCMS-XSS3.md
- https://vuldb.com/?ctiid_331640=
- https://vuldb.com/?id_331640=
- https://vuldb.com/?submit_680851=
- https://vuldb.com/?submit_680852=
- https://vuldb.com/?submit_680853=
- https://github.com/21151213732/CVE/blob/main/FoxCMS-XSS2.md
- https://github.com/21151213732/CVE/blob/main/FoxCMS-XSS3.md



