CVE-2025-53642

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
References
Link Resource
https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*

History

22 Aug 2025, 16:52

Type Values Removed Values Added
References () https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg - () https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg - Third Party Advisory, Issue Tracking
First Time Psu haxcms-php
Psu haxcms-nodejs
Psu
CPE cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*
cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) haxcms-nodejs y haxcms-php son backends para HAXcms. La función de cierre de sesión de la aplicación no cierra la sesión del usuario ni borra sus cookies. Además, la aplicación emite un token de actualización al cerrar sesión. Esta vulnerabilidad se corrigió en la versión 11.0.6.

11 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 18:15

Updated : 2025-08-22 16:52


NVD link : CVE-2025-53642

Mitre link : CVE-2025-53642

CVE.ORG link : CVE-2025-53642


JSON object : View

Products Affected

psu

  • haxcms-php
  • haxcms-nodejs
CWE
CWE-613

Insufficient Session Expiration