PT-2026-47039 · Hax Cms · Hax Cms
CVE-2026-46398
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HAX CMS versions 25.0.0 through 25.x
Description
The
haxcms refresh token cookie is configured without the Secure flag. This configuration allows the cookie to be transmitted over unencrypted HTTP connections, which enables an attacker to steal the token using packet sniffing on the network.Recommendations
Update to version 26.0.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hax Cms