HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for the site. This content is then rendered in the generated HAX site. Although the application does not allow users to supply a `script` tag, it does allow the use of other HTML tags to run JavaScript. Version 11.0.0 fixes the issue.
History

Fri, 20 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Haxtheweb
Haxtheweb haxcms-nodejs
Haxtheweb haxcms-php
CPEs cpe:2.3:a:haxtheweb:haxcms-nodejs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:haxtheweb:haxcms-php:*:*:*:*:*:*:*:*
Vendors & Products Haxtheweb
Haxtheweb haxcms-nodejs
Haxtheweb haxcms-php

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Description HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for the site. This content is then rendered in the generated HAX site. Although the application does not allow users to supply a `script` tag, it does allow the use of other HTML tags to run JavaScript. Version 11.0.0 fixes the issue.
Title Hax CMS Stored Cross-Site Scripting vulnerability
Weaknesses CWE-79
CWE-80
CWE-87
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-09T21:00:15.808Z

Updated: 2025-06-10T15:30:09.073Z

Reserved: 2025-06-02T10:39:41.634Z

Link: CVE-2025-49137

cve-icon Vulnrichment

Updated: 2025-06-10T14:22:46.643Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-09T21:15:46.890

Modified: 2025-06-20T14:28:09.933

Link: CVE-2025-49137

cve-icon Redhat

No data.