SQL Injection Vulnerability in FoxCMS by FoxCMS
CVE-2025-56630
7.3HIGH
What is CVE-2025-56630?
FoxCMS versions up to 1.2.5 have a vulnerability allowing SQL Injection through the 'column_model' parameter in the app/admin/controller/Column.php file. This flaw can enable attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data. Web administrators using affected versions must implement proper input validation and upgrade to the latest version to mitigate the risk.