PT-2025-24564 · Hax Cms · Hax Cms

Lfgberg

+1

·

Published

2025-06-09

·

Updated

2025-06-09

·

CVE-2025-49139

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HAX CMS PHP versions prior to 11.0.0
Description The issue allows an authenticated attacker to create a HAX site with a website block that can load another site in an iframe, potentially leading to phishing attacks. When a user visits the malicious HAX site, their browser will query the supplied URL, which can be controlled by the attacker. This can be exploited by convincing another user to visit the malicious site, allowing the attacker to harvest credentials.
Recommendations For versions prior to 11.0.0, update to version 11.0.0 to resolve the issue. As a temporary workaround, consider restricting the use of the website block feature in the HAX site editor to minimize the risk of exploitation.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-49139
GHSA-V3PH-2Q5Q-CG88

Affected Products

Hax Cms