← Volver a CVEs
CVE-2025-54134
MEDIUM6.5
Descripcion
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9.
Detalles CVE
Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado7/21/2025
Ultima modificacion7/30/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
psu:haxcms-nodejs
Debilidades (CWE)
CWE-20CWE-248CWE-703
Referencias
https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/listFiles.js#L22(security-advisories@github.com)
https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/saveFile.js#L52(security-advisories@github.com)
https://github.com/haxtheweb/haxcms-nodejs/commit/e9773d1996233f9bafb06832b8220ec2a98bab34(security-advisories@github.com)
https://github.com/haxtheweb/issues/security/advisories/GHSA-pjj3-j5j6-qj27(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.