HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7.
History

Wed, 30 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-nodejs
CPEs cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
Vendors & Products Psu
Psu haxcms-nodejs
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 23 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Haxtheweb
Haxtheweb haxcms-nodejs
Vendors & Products Haxtheweb
Haxtheweb haxcms-nodejs

Tue, 22 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 21:30:00 +0000

Type Values Removed Values Added
Description HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAX CMS uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7. HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7.
Title HAX CMS PHP's Insecure Default Configuration Leads to Unauthenticated Access HAXcms's Insecure Default Configuration Leads to Unauthenticated Access

Mon, 21 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
Description HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAX CMS uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7.
Title HAX CMS PHP's Insecure Default Configuration Leads to Unauthenticated Access
Weaknesses CWE-1188
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-21T20:36:43.580Z

Updated: 2025-07-22T19:56:43.124Z

Reserved: 2025-07-16T23:53:40.509Z

Link: CVE-2025-54127

cve-icon Vulnrichment

Updated: 2025-07-22T19:56:38.713Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T21:15:26.403

Modified: 2025-07-30T17:03:34.940

Link: CVE-2025-54127

cve-icon Redhat

No data.