GHSA-59g8-h59f-8hjp
NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
Quick fix
GHSA-59g8-h59f-8hjp — @haxtheweb/haxcms-nodejs: upgrade to the fixed version with the command below.
npm install @haxtheweb/haxcms-nodejs@11.0.8Details
### Summary The NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.
### Details The `contentSecurityPolicy` value is explicitly disabled in the application's Helmet configuration in `app.js`.

#### Affected Resources - [app.js:52](https://github.com/haxtheweb/haxcms-nodejs/blob/b1f95880b42fea6ed07855b5804b29b182ec5e07/src/app.js#L52)
### PoC To reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without a CSP configured.
### Impact In conjunction with an XSS vulnerability, an attacker could execute arbitrary scripts and exfiltrate data, including session tokens and sensitive local data.
#### Additional Information - [OWASP: Content Security Policy](https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 11.0.8npm install @haxtheweb/haxcms-nodejs@11.0.8