CVE-2025-40727: Reflected Cross-Site Scripting (XSS) in Phoenix CMS
A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code via 's' GET parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40727?
CVE-2025-40727 is classified as a high severity vulnerability due to its ability to allow remote code execution via reflected XSS.
How do I fix CVE-2025-40727?
To fix CVE-2025-40727, you should validate and sanitize all user inputs, particularly the 's' GET parameter in the '/search' endpoint.
Who is affected by CVE-2025-40727?
CVE-2025-40727 affects users of the Phoenix Site CMS software that have not implemented sufficient input validation measures.
What are the potential impacts of CVE-2025-40727?
The potential impacts of CVE-2025-40727 include reducing user trust, compromising sensitive data, and allowing unauthorized actions in the web application.
Can CVE-2025-40727 be exploited remotely?
Yes, CVE-2025-40727 can be exploited remotely by attackers who can craft malicious requests to the vulnerable '/search' endpoint.