HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3. | |
Title | HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-08T16:06:33.976Z
Updated: 2025-04-08T20:00:56.916Z
Reserved: 2025-04-01T21:57:32.957Z
Link: CVE-2025-32028

Updated: 2025-04-08T20:00:49.026Z

Status : Awaiting Analysis
Published: 2025-04-08T16:15:28.180
Modified: 2025-04-08T20:15:28.090
Link: CVE-2025-32028

No data.