{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-11T03:26:38.034","vulnerabilities":[{"cve":{"id":"CVE-2025-49141","sourceIdentifier":"security-advisories@github.com","published":"2025-06-09T21:15:47.360","lastModified":"2025-07-30T17:36:08.923","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later passes this input into `proc_open`, yielding OS command injection. An authenticated attacker can craft a URL string that bypasses the validation checks employed by the `filter_var` and `strpos` functions in order to execute arbitrary OS commands on the backend server. The attacker can exfiltrate command output via an HTTP request. Version 11.0.3 contains a patch for the issue."},{"lang":"es","value":"HAX CMS PHP permite a los usuarios gestionar su universo de micrositios con un backend PHP. Antes de la versión 11.0.3, la función `gitImportSite` obtenía una URL de una solicitud POST y no validaba adecuadamente la entrada del usuario. La función `set_remote` posteriormente pasa esta entrada a `proc_open`, lo que provoca la inyección de comandos del sistema operativo. Un atacante autenticado puede manipular una URL que omita las comprobaciones de validación empleadas por las funciones `filter_var` y `strpos` para ejecutar comandos arbitrarios del sistema operativo en el servidor backend. El atacante puede extraer la salida del comando mediante una solicitud HTTP. La versión 11.0.3 incluye un parche para este problema."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:*","versionEndExcluding":"11.0.3","matchCriteriaId":"42D865D7-81C8-45CD-AC00-FC519C682207"},{"vulnerable":true,"criteria":"cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:*","versionEndExcluding":"11.0.0","matchCriteriaId":"A72C09C8-71A3-4B4F-BA0E-CF75016F5112"}]}]}],"references":[{"url":"https://github.com/haxtheweb/haxcms-nodejs/commit/5131fea6b6be611db76a618f89bd2e164752e9b3","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-g4cf-pp4x-hqgw","source":"security-advisories@github.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-g4cf-pp4x-hqgw","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}}]}