CVE-2025-54129 is a user enumeration vulnerability affecting HAXiam versions 11.0.4 and below, a packaging wrapper for HAXcms. An authenticated attacker can differentiate between valid and invalid user accounts by observing HTTP response codes (200 for valid, 404 for invalid). This medium-severity vulnerability (CVSS 4.3) has a low attack complexity and could lead to information disclosure, potentially aiding further attacks like site defacement when combined with other weaknesses. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0.5CPE matchmatch criteria | cpe:2.3:a:psu:haxiam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.