Weak Password Recovery in QianFox FoxCMS Admin Interface
CVE-2026-9609
Key Information:
Badges
What is CVE-2026-9609?
A vulnerability in QianFox FoxCMS versions up to 1.2.6 affects the Admin.php file's Edit function, leading to weak password recovery mechanisms. This security flaw allows an attacker to manipulate the password recovery process remotely, potentially compromising user accounts. The exploit details are publicly accessible, and despite an early warning to the project team via an issue report, no action has been taken to address this critical weakness in the software.
Affected Version(s)
FoxCMS 1.2.0
FoxCMS 1.2.1
FoxCMS 1.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
