haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
References
| Link | Resource |
|---|---|
| https://github.com/haxtheweb/issues/security/advisories/GHSA-g4f5-5w5j-p5jg | Third Party Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-07-11 18:15
Updated : 2025-08-22 16:52
NVD link : CVE-2025-53642
Mitre link : CVE-2025-53642
CVE.ORG link : CVE-2025-53642
JSON object : View
Products Affected
psu
- haxcms-nodejs
- haxcms-php
CWE
CWE-613
Insufficient Session Expiration
