CVE-2025-49141 | haxtheweb haxcms up to 11.0.2 HTTP Request gitImportSite proc_open os command injection (GHSA-g4cf-pp4x-hqgw / EUVD-2025-17578)
A vulnerability was found in haxtheweb haxcms up to 11.0.2 and classified as critical. Affected by this issue is the function gitImportSite of the component HTTP Request Handler. The manipulation of the argument proc_open leads to os command injection.
This vulnerability is handled as CVE-2025-49141. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.