CVE-2025-32028 | HAX CMS PHP up to 10.0.2 HAXCMSFile.php save unrestricted upload (GHSA-vj5q-3jv2-cg5p)
A vulnerability was found in HAX CMS PHP up to 10.0.2. It has been rated as critical. This issue affects the function Save of the file HAXCMSFile.php. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-32028. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.