CVE-2025-56236
C# vulnerability analysis and mitigation

Overview

FormCms version 0.5.5 contains a stored cross-site scripting (XSS) vulnerability that was discovered and reported on July 8, 2025. The vulnerability affects the avatar upload feature of the application and has been assigned identifier CVE-2025-56236. The issue has received a CVSS v3.1 base score of 6.1 (Medium) from CISA-ADP (NVD).

Technical details

The vulnerability exists in the avatar upload feature where authenticated users can upload .html files containing malicious JavaScript code through the /api/profile/avatar endpoint. These uploaded files are stored at publicly accessible locations under /files/avatar/[random-id].html. The files remain accessible without any authentication or access control measures in place (GitHub Issue).

Impact

When a privileged user, such as a Super Admin, accesses the malicious file either directly or through social engineering, the embedded JavaScript executes in their browser context. This allows attackers to perform unauthorized API operations with the victim's elevated privileges, including full CRUD (Create, Read, Update, Delete) operations on users, roles, and other sensitive application data (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-57803HIGH8.8
  • C#C#
  • Magick.NET-Q8-x86
NoYesAug 26, 2025
CVE-2025-55298HIGH8.8
  • C#C#
  • Magick.NET-Q16-HDRI-x86
NoYesAug 26, 2025
CVE-2025-55212HIGH7.5
  • C#C#
  • cpe:2.3:a:imagemagick:imagemagick
NoYesAug 26, 2025
CVE-2025-56236MEDIUM6.1
  • C#C#
  • FormCMS
NoYesAug 28, 2025
CVE-2025-57807LOW3.8
  • C#C#
  • ImageMagick-perl
NoYesSep 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management