haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21181 haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Aug 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-nodejs
Psu haxcms-php
CPEs cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*
Vendors & Products Psu
Psu haxcms-nodejs
Psu haxcms-php

Mon, 14 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}


Fri, 11 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
Description haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Title haxcms-nodejs and haxcms-php Improperly Terminate Sessions
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-07-14T14:17:55.724Z

Reserved: 2025-07-07T14:20:38.391Z

Link: CVE-2025-53642

cve-icon Vulnrichment

Updated: 2025-07-14T14:17:52.521Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-11T18:15:35.123

Modified: 2025-08-22T16:52:08.603

Link: CVE-2025-53642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:06:09Z