Authorization Flaw in HAX CMS Affects NodeJs and PHP Installations
CVE-2025-54378

8.3HIGH

Key Information:

Vendor

Haxtheweb

Status
Vendor
CVE Published:
26 July 2025

What is CVE-2025-54378?

HAX CMS encompasses both PHP and NodeJs backends that facilitate the management of microsites. In versions 11.0.13 and earlier for haxcms-nodejs and in versions 11.0.8 and earlier for haxcms-php, an inherent flaw has been identified in the API endpoints. These endpoints fail to implement necessary authorization checks, allowing unauthorized users to perform actions on resources without proper permission verification. While the endpoints enforce user authentication, they overlook the critical step of validating user authorization before executing operations. This issue has been resolved in haxcms-nodejs version 11.0.14 and haxcms-php version 11.0.9, ensuring that operations are only permitted for users with appropriate permissions.

Affected Version(s)

issues < 11.0.14

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54378 : Authorization Flaw in HAX CMS Affects NodeJs and PHP Installations