← voltar
CVE-2025-32028

HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution

CVSS 10 CRITICALEPSS 1.6%CWE-434
HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
haxtheweb · issues

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →