Executive brief
HAX CMS is a content management system that uses API endpoints to manage sites and content. An authenticated attacker can bypass authorization checks to access, modify, or delete other users' sites and content, and potentially access sensitive configuration files containing credentials.
Technical details
The HAX CMS API endpoints verify user authentication (via JWT) but fail to check authorization before performing operations on resources. Multiple API functions (createNode, saveNode, deleteNode, listSites, createSite, getConfig, cloneSite, deleteSite, downloadSite, archiveSite) lack proper access control, allowing any authenticated user to interact with any resource. Attack requires valid authentication credentials but no special privileges. An authenticated attacker can enumerate, modify, or delete arbitrary sites and nodes belonging to other users, and access the application configuration which may contain cleartext credentials. Patches are available: version 11.0.14 for the Node.js version and 11.0.9 for the PHP version.
Affected products
- HAX CMS <=11.0.5 (Node.js version); <=11.0.5 (PHP version)
- HAX haxcms-nodejs <=11.0.5
- HAX haxcms-php <=11.0.5
Timeline
- 2025-07-25: disclosed: Advisory published
- 2025-07-25: patched: Node.js version patched to 11.0.14