6.5
CVE-2025-53642
- EPSS 0.17%
- Veröffentlicht 11.07.2025 17:33:05
- Zuletzt bearbeitet 22.08.2025 16:52:08
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
haxcms-nodejs and haxcms-php Improperly Terminate Sessions
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Psu ≫ Haxcms-nodejs SwPlatformnode.js Version < 11.0.6
Psu ≫ Haxcms-php Version < 11.0.6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| security-advisories@github.com | 4.8 | 2.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg