CVE-2025-53642

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
References
Link Resource
https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*

History

22 Aug 2025, 16:52

Type Values Removed Values Added
First Time Psu haxcms-php
Psu
Psu haxcms-nodejs
References () https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg - () https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg - Third Party Advisory, Issue Tracking
CPE cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*
cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*

15 Jul 2025, 13:14

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 18:15

Updated : 2025-08-22 16:52


NVD link : CVE-2025-53642

Mitre link : CVE-2025-53642

CVE.ORG link : CVE-2025-53642


JSON object : View

Products Affected

psu

  • haxcms-nodejs
  • haxcms-php
CWE
CWE-613

Insufficient Session Expiration