Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
- Severity:
- Medium
Description
An unauthenticated information disclosure vulnerability exists in the PSU deployment of HAX CMS via the haxPsuUsage API endpoint. This allows any remote unauthenticated user to retrieve a full list of PSU websites hosted on HAX CMS. When chained with other authorization issues (e.g.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 10.0.1
References
Related Issues
- evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API - CVE-2025-67419
- evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API - CVE-2025-67427
- jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin - CVE-2025-9910
- React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button - CVE-2025-3191
You might also like:
- Tags:
- npm
- @haxtheweb/open-apis
Anything's wrong? Let us know Last updated on June 05, 2025


