Information Disclosure in HAXiam Affects HAXcms
CVE-2025-54129

4.3MEDIUM

Key Information:

Vendor

Haxtheweb

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-54129?

The HAXiam framework, designed for managing microsites via HAXcms, poses a security risk in its versions 11.0.4 and below. The application inadvertently reveals valid user accounts by returning a 200 OK response for valid usernames and a 404 Not Found for invalid ones. This behavior enables malicious actors to automate username brute force attacks, confirming the existence of accounts. When leveraged alongside other vulnerabilities, such as insufficient authorization checks, this can lead to unauthorized modifications of users' microsites. The vulnerability has been addressed in version 11.0.5.

Affected Version(s)

issues < 11.0.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54129 : Information Disclosure in HAXiam Affects HAXcms