CVE-2025-32028

CRITICAL

PSU Haxcms-php < 10.0.3 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and only blocks ’.php’, ’.sh’, ’.js’, and ’.css’ files. The existing logic causes the system to "fail open" rather than "fail closed." This vulnerability is fixed in 10.0.3.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/haxtheweb/issues/security/advisories/GHSA-vj5q-3jv2-cg5p

Scores

CVSS v3 9.9
EPSS 0.0062
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
psu/haxcms-php 9.0.0 - 10.0.3
Published Apr 08, 2025
Tracked Since Feb 18, 2026