SQL Injection Vulnerability in FoxCMS by FoxCMS
CVE-2025-56630

7.3HIGH

Key Information:

Vendor

FoxCMS

Status
Vendor
CVE Published:
8 September 2025

What is CVE-2025-56630?

FoxCMS versions up to 1.2.5 have a vulnerability allowing SQL Injection through the 'column_model' parameter in the app/admin/controller/Column.php file. This flaw can enable attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data. Web administrators using affected versions must implement proper input validation and upgrade to the latest version to mitigate the risk.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-56630 : SQL Injection Vulnerability in FoxCMS by FoxCMS