Cross-Site Scripting Vulnerability in HAX CMS by HAX Technology
CVE-2025-49139
5.3MEDIUM
What is CVE-2025-49139?
HAX CMS prior to version 11.0.0 contains a vulnerability that allows authenticated users to create a website block that loads an external URL in an iframe. This functionality can be exploited by an attacker who controls the target URL, enabling them to conduct phishing attacks through malicious HAX sites. When unsuspecting users visit a compromised site, their browsers will interact with the attacker's server, allowing for the potential theft of sensitive information such as credentials. Version 11.0.0 has remedied this issue with a patch.
Affected Version(s)
issues < 11.0.0