GHSA-54vw-f4xf-f92j

Suggest an improvement
Source
https://github.com/advisories/GHSA-54vw-f4xf-f92j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-54vw-f4xf-f92j/GHSA-54vw-f4xf-f92j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-54vw-f4xf-f92j
Aliases
Related
Published
2025-07-21T21:12:44Z
Modified
2025-07-23T13:59:23.597612Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
HAX CMS application pages vulnerable to clickjacking
Details

Summary

All pages within the HAX CMS application do not contain headers to stop other websites from loading the site within an iframe. This applies to both the CMS and generated sites.

PoC

To replicate this vulnerability, load the target page in an iframe and observe the rendered content.

image

Impact

An unauthenticated attacker can load the standalone login page or other sensitive functionality within an iframe, performing a UI redressing attack (Clickjacking). This can be used to perform social engineering attacks to attempt to coerce users into performing unintended actions within the HAX CMS application.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2025-07-23T00:15:25Z",
    "severity": "MODERATE",
    "github_reviewed_at": "2025-07-21T21:12:44Z",
    "cwe_ids": [
        "CWE-1021"
    ]
}
References

Affected packages

npm / @haxtheweb/haxcms-nodejs

Package

Name
@haxtheweb/haxcms-nodejs
View open source insights on deps.dev
Purl
pkg:npm/%40haxtheweb/haxcms-nodejs

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.13

Packagist / elmsln/haxcms

Package

Name
elmsln/haxcms
Purl
pkg:composer/elmsln/haxcms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.8

Affected versions

0.*

0.0.1
0.1.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.9.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3