haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
2025-07-11T18:15:35.123
2025-08-22T16:52:08.603
Analyzed
CVSSv3.1: 4.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | psu | haxcms-nodejs | < 11.0.6 | Yes |
| Application | psu | haxcms-php | < 11.0.6 | Yes |