HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.
History

Wed, 30 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-nodejs
CPEs cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
Vendors & Products Psu
Psu haxcms-nodejs
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 22 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Haxtheweb
Haxtheweb haxcms-nodejs
Vendors & Products Haxtheweb
Haxtheweb haxcms-nodejs

Mon, 21 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.
Title HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-21T20:46:31.660Z

Updated: 2025-07-22T20:43:50.054Z

Reserved: 2025-07-16T23:53:40.509Z

Link: CVE-2025-54128

cve-icon Vulnrichment

Updated: 2025-07-22T20:43:46.384Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T21:15:26.553

Modified: 2025-07-30T17:04:15.720

Link: CVE-2025-54128

cve-icon Redhat

No data.