Information Disclosure in HAXiam Affects HAXcms
CVE-2025-54129
4.3MEDIUM
What is CVE-2025-54129?
The HAXiam framework, designed for managing microsites via HAXcms, poses a security risk in its versions 11.0.4 and below. The application inadvertently reveals valid user accounts by returning a 200 OK response for valid usernames and a 404 Not Found for invalid ones. This behavior enables malicious actors to automate username brute force attacks, confirming the existence of accounts. When leveraged alongside other vulnerabilities, such as insufficient authorization checks, this can lead to unauthorized modifications of users' microsites. The vulnerability has been addressed in version 11.0.5.
Affected Version(s)
issues < 11.0.5