haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
History

Mon, 14 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}


Fri, 11 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
Description haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Title haxcms-nodejs and haxcms-php Improperly Terminate Sessions
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-11T17:33:05.861Z

Updated: 2025-07-14T14:17:55.724Z

Reserved: 2025-07-07T14:20:38.391Z

Link: CVE-2025-53642

cve-icon Vulnrichment

Updated: 2025-07-14T14:17:52.521Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-11T18:15:35.123

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-53642

cve-icon Redhat

No data.