Insecure Default Configuration in HAXcms with NodeJS Backend
CVE-2025-54127
9.3CRITICAL
What is CVE-2025-54127?
The HAXcms with a NodeJS backend is affected by an insecure default configuration that allows users to start the server in any HAXsite without proper authorization or authentication checks. The default setting for HAXcms versions 11.0.6 and earlier allows for 'HAXCMS_DISABLE_JWT_CHECKS' to be enabled, leading to configurations that lack session authentication. This vulnerability can be exploited if the software is deployed without proper modifications, potentially exposing sensitive data and functionalities. The issue has been resolved in version 11.0.7.
Affected Version(s)
issues < 11.0.7