HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9.
History

Wed, 30 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-nodejs
CPEs cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
Vendors & Products Psu
Psu haxcms-nodejs
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Wed, 23 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9.
Title HAX CMS NodeJs's Improper Error Handling Leads to Denial of Service
Weaknesses CWE-20
CWE-248
CWE-703
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-21T20:58:35.724Z

Updated: 2025-07-23T18:30:23.112Z

Reserved: 2025-07-16T23:53:40.510Z

Link: CVE-2025-54134

cve-icon Vulnrichment

Updated: 2025-07-23T18:30:13.954Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T21:15:26.863

Modified: 2025-07-30T17:07:18.563

Link: CVE-2025-54134

cve-icon Redhat

No data.