Executive brief
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Affected products
- Packagist elmsln/haxcms
Junglewise Threat Intelligence
CVE-2025-49138 · Severity: low · CVSS 3.1 · Published 2025-06-09
Technologies: elmsln/haxcms (Packagist). Vendors: Packagist.
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter