PT-2025-30345 · Unknown · Haxcms-Nodejs

Asareynolds

·

Published

2025-07-21

·

Updated

2025-07-22

·

CVE-2025-54128

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions HAX CMS NodeJs versions 11.0.7 and below
Description HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. The NodeJS version of HAX CMS has a disabled Content Security Policy (CSP) in versions 11.0.7 and below. This configuration does not protect against cross-site-scripting attacks because the contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js.
Recommendations HAX CMS NodeJs version 11.0.8 or later should be used.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54128
GHSA-59G8-H59F-8HJP

Affected Products

Haxcms-Nodejs