Skip to main content

CVE-2025-54129: CWE-204: Observable Response Discrepancy in haxtheweb issues

Medium
VulnerabilityCVE-2025-54129cvecve-2025-54129cwe-204
Published: Mon Jul 21 2025 (07/21/2025, 20:53:26 UTC)
Source: CVE Database V5
Vendor/Project: haxtheweb
Product: issues

Description

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response when requesting the data of an invalid user. This can be used to infer the existence of valid user accounts. An authenticated attacker can use automated tooling to brute force potential usernames and use the application's response to identify valid accounts. This can be used in conjunction with other vulnerabilities, such as the lack of authorization checks, to enumerate and deface another user's sites. This is fixed in version 11.0.5.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-07-16T23:53:40.509Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 687eaa92a83201eaac1449a2

Added to database: 7/21/2025, 9:01:06 PM

Last updated: 7/21/2025, 9:01:06 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats