Directory Traversal Vulnerability in FoxCMS v2.0.6 by QianFox
CVE-2025-45239

5.3MEDIUM

Key Information:

Vendor

QianFox

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2025-45239?

A vulnerability in FoxCMS version 2.0.6 allows attackers to exploit a flaw in the restores method located in DataBackup.php. This weakness can enable unauthorized access to the file system, potentially allowing an attacker to read sensitive files and directories through directory traversal techniques. Proper input validation and sanitization mechanisms should be enforced to mitigate such risks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-45239 : Directory Traversal Vulnerability in FoxCMS v2.0.6 by QianFox