CVE-2025-53642 | haxcms-nodejs.operations/haxcms-php.operations prior 11.0.6 Refresh Token logout session expiration (GHSA-g4f5-5w5j-p5jg / EUVD-2025-21181)
A vulnerability was found in haxcms-nodejs.operations and haxcms-php.operations. It has been classified as problematic. Impacted is the function Logout of the component Refresh Token Handler. Performing manipulation results in session expiration.
This vulnerability is reported as CVE-2025-53642. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.