HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Psu
Psu haxcms-nodejs |
|
CPEs | cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Psu
Psu haxcms-nodejs |
|
Metrics |
cvssV3_1
|
Wed, 23 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9. | |
Title | HAX CMS NodeJs's Improper Error Handling Leads to Denial of Service | |
Weaknesses | CWE-20 CWE-248 CWE-703 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-21T20:58:35.724Z
Updated: 2025-07-23T18:30:23.112Z
Reserved: 2025-07-16T23:53:40.510Z
Link: CVE-2025-54134

Updated: 2025-07-23T18:30:13.954Z

Status : Analyzed
Published: 2025-07-21T21:15:26.863
Modified: 2025-07-30T17:07:18.563
Link: CVE-2025-54134

No data.