Executive brief
HAX CMS is a content management system used to build and manage microsites. A security flaw in the PHP version of the software allows an authenticated user to overwrite critical system files. By modifying internal configuration files, an attacker can take full control of the server, potentially leading to the theft of customer data, website defacement, or a total service outage.
Technical details
The 'saveOutline' function in the PHP backend of HAX CMS fails to properly restrict the 'location' parameter, allowing it to target files within the site directory, including the '.git' folder. While the application attempts to strip path traversal sequences (../), it does not prevent writing to sensitive subdirectories already present in the relative root. An authenticated attacker can exploit this by overwriting '.git/config' to define a malicious Git filter. Because 'saveOutline' automatically triggers a Git commit, the malicious filter command is executed immediately on the server. This results in full remote code execution (RCE) with the privileges of the web server user. The issue is resolved in version 26.0.0.
Affected products
- haxtheweb HAX CMS (PHP version) < 26.0.0
Timeline
- 2026-05-12: advisory: Vendor advisory published via GitHub
- 2026-06-05: disclosed: CVE published to NVD