Authorization Flaw in HAX CMS Affects NodeJs and PHP Installations
CVE-2025-54378
What is CVE-2025-54378?
HAX CMS encompasses both PHP and NodeJs backends that facilitate the management of microsites. In versions 11.0.13 and earlier for haxcms-nodejs and in versions 11.0.8 and earlier for haxcms-php, an inherent flaw has been identified in the API endpoints. These endpoints fail to implement necessary authorization checks, allowing unauthorized users to perform actions on resources without proper permission verification. While the endpoints enforce user authentication, they overlook the critical step of validating user authorization before executing operations. This issue has been resolved in haxcms-nodejs version 11.0.14 and haxcms-php version 11.0.9, ensuring that operations are only permitted for users with appropriate permissions.
Affected Version(s)
issues < 11.0.14