HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10386 HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 31 Jul 2025 02:45:00 +0900

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-php
CPEs cpe:2.3:a:haxtheweb:hax:*:*:*:*:*:*:*:* cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*
Vendors & Products Haxtheweb
Haxtheweb hax
Psu
Psu haxcms-php

Wed, 18 Jun 2025 23:15:00 +0900

Type Values Removed Values Added
First Time appeared Haxtheweb
Haxtheweb hax
CPEs cpe:2.3:a:haxtheweb:hax:*:*:*:*:*:*:*:*
Vendors & Products Haxtheweb
Haxtheweb hax

Wed, 09 Apr 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 01:15:00 +0900

Type Values Removed Values Added
Description HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.
Title HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-08T20:00:56.916Z

Reserved: 2025-04-01T21:57:32.957Z

Link: CVE-2025-32028

cve-icon Vulnrichment

Updated: 2025-04-08T20:00:49.026Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-08T16:15:28.180

Modified: 2025-07-30T17:36:18.587

Link: CVE-2025-32028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses