Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x3x5-7h4h-gwxg | HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack |
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb haxcms-nodejs Haxtheweb haxcms-php |
|
| Vendors & Products |
Haxtheweb
Haxtheweb haxcms-nodejs Haxtheweb haxcms-php |
Fri, 05 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook. Version 26.0.0 patches the issue. | |
| Title | HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack | |
| Weaknesses | CWE-522 CWE-79 CWE-922 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T15:55:20.156Z
Reserved: 2026-05-14T19:12:32.754Z
Link: CVE-2026-46511
Updated: 2026-06-08T15:52:36.613Z
Status : Deferred
Published: 2026-06-05T19:16:34.267
Modified: 2026-06-08T17:16:52.020
Link: CVE-2026-46511
No data.
OpenCVE Enrichment
Updated: 2026-06-05T20:45:04Z
Github GHSA