TROYANOSYVIRUS
Back to CVEs

CVE-2025-54129

MEDIUM
4.3

Description

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response when requesting the data of an invalid user. This can be used to infer the existence of valid user accounts. An authenticated attacker can use automated tooling to brute force potential usernames and use the application's response to identify valid accounts. This can be used in conjunction with other vulnerabilities, such as the lack of authorization checks, to enumerate and deface another user's sites. This is fixed in version 11.0.5.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published7/21/2025
Last Modified8/22/2025
Sourcenvd
Honeypot Sightings0

Affected Products

psu:haxiam

Weaknesses (CWE)

CWE-204

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.