PT-2025-30347 · Hax Cms+1 · Hax Cms+1

Lfgberg

·

Published

2025-07-21

·

Updated

2025-07-22

·

CVE-2025-54129

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HAXiam versions 11.0.4 and below
Description HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. The application returns a 200 response when requesting the data of a valid user and a 404 response when requesting the data of an invalid user. This behavior can be used to infer the existence of valid user accounts. An authenticated attacker can use automated tooling to brute force potential usernames and use the application's response to identify valid accounts. This can be used in conjunction with other vulnerabilities, such as the lack of authorization checks, to enumerate and deface another user's sites.
Recommendations Update HAXiam to version 11.0.5 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54129
GHSA-WH3H-VFCV-M5G5

Affected Products

Hax Cms
Haxiam