Vulnerabilities/

Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint

Severity:
Medium

Description

An unauthenticated information disclosure vulnerability exists in the PSU deployment of HAX CMS via the haxPsuUsage API endpoint. This allows any remote unauthenticated user to retrieve a full list of PSU websites hosted on HAX CMS. When chained with other authorization issues (e.g.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@haxtheweb/open-apis
Anything's wrong? Let us know Last updated on June 05, 2025