PT-2026-47040 · Hax Cms · Hax Cms
CVE-2026-46400
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
HAX CMS versions 11.0.6 through 24.x
Description
The file upload functionality in HAXCMS PHP validates file extensions using a regex pattern but fails to verify the actual file content or MIME type (Multipurpose Internet Mail Extensions, a standard that indicates the nature and format of a document). This allows the upload of malicious files, such as PHP webshells, disguised as legitimate images, which can lead to remote code execution.
Recommendations
Update to version 25.0.0.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hax Cms