HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual file content or MIME type. This allows attackers to upload malicious files (e.g., PHP webshells) disguised as legitimate image files, potentially leading to remote code execution. Version 25.0.0 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb haxcms-php |
|
| Vendors & Products |
Haxtheweb
Haxtheweb haxcms-php |
Fri, 05 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual file content or MIME type. This allows attackers to upload malicious files (e.g., PHP webshells) disguised as legitimate image files, potentially leading to remote code execution. Version 25.0.0 contains a fix for the issue. | |
| Title | HAXCMS PHP has a File Upload Validation Bypass | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-05T19:15:29.745Z
Updated: 2026-06-08T15:50:54.946Z
Reserved: 2026-05-13T21:04:10.932Z
Link: CVE-2026-46400
Updated: 2026-06-08T15:48:43.983Z
Status : Deferred
Published: 2026-06-05T20:17:34.073
Modified: 2026-06-08T17:16:51.057
Link: CVE-2026-46400
No data.
ReportizFlow