Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HAXcms createSite SSRF Enables Arbitrary File Read
Vulnerability Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access. Version 26.0.0 contains a fix.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
HAX 代码问题漏洞
Vulnerability Description
HAX是HAX The Web开源的一个HAX+CMS使用PHP后端管理的微型网站。 HAX 26.0.0之前版本存在代码问题漏洞,该漏洞源于存在经过身份验证的服务端请求伪造漏洞,可能导致经过身份验证的用户获取任意内部或本地资源并将响应写入Web可访问目录,实现任意文件读取和内部网络访问。
CVSS Information
N/A
Vulnerability Type
N/A