We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-49137

Hax CMS Stored Cross-Site Scripting vulnerability



Description

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for the site. This content is then rendered in the generated HAX site. Although the application does not allow users to supply a `script` tag, it does allow the use of other HTML tags to run JavaScript. Version 11.0.0 fixes the issue.

Reserved 2025-06-02 | Published 2025-06-09 | Updated 2025-06-09 | Assigner GitHub_M


HIGH: 8.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-87: Improper Neutralization of Alternate XSS Syntax

Product status

< 11.0.0
affected

References

github.com/...issues/security/advisories/GHSA-2vc4-3hx7-v7v7

github.com/...ommit/0dd3e98fe2fadd0793b667d4af2aac230980e0f8

cve.org (CVE-2025-49137)

nvd.nist.gov (CVE-2025-49137)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-49137

Support options

Helpdesk Chat, Email, Knowledgebase