Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-49139

Опубликовано: 09 июн. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the HAX site is visited, the client's browser will query the supplied URL. An authenticated attacker can create a HAX site with a website block pointing at an attacker-controlled server running Responder or a similar tool. The attacker can then conduct a phishing attack by convincing another user to visit their malicious HAX site to harvest credentials. Version 11.0.0 contains a patch for the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
Версия до 11.0.0 (исключая)
cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*
Версия до 11.0.0 (исключая)

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 5.3
github
8 месяцев назад

@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-1021