PT-2025-30361 · Hax Cms · Hax Cms

Lfgberg

+1

·

Published

2025-07-21

·

Updated

2025-07-23

·

CVE-2025-54139

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HAX CMS versions 11.0.7 and below (PHP) HAX CMS versions 11.0.12 and below (NodeJS)
Description HAX CMS does not include headers to prevent websites from loading the application within an iframe. This affects both the CMS and generated sites. An unauthenticated attacker can load sensitive functionality, such as the login page, within an iframe, enabling a UI redressing attack (clickjacking). This can be used to perform social engineering attacks to coerce users into performing unintended actions.
Recommendations HAX CMS versions 11.0.7 and below (PHP): Update to version 11.0.8 or later. HAX CMS versions 11.0.12 and below (NodeJS): Update to version 11.0.13 or later.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-54139
GHSA-54VW-F4XF-F92J

Affected Products

Hax Cms