Information Disclosure in HAXiam Affects HAXcms
CVE-2025-54129
What is CVE-2025-54129?
The HAXiam framework, designed for managing microsites via HAXcms, poses a security risk in its versions 11.0.4 and below. The application inadvertently reveals valid user accounts by returning a 200 OK response for valid usernames and a 404 Not Found for invalid ones. This behavior enables malicious actors to automate username brute force attacks, confirming the existence of accounts. When leveraged alongside other vulnerabilities, such as insufficient authorization checks, this can lead to unauthorized modifications of users' microsites. The vulnerability has been addressed in version 11.0.5.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
issues < 11.0.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
