A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

Subscriptions

Vendors Products

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 23 Mar 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Title MacCMS Timming API Endpoint Timming.php weak authentication
First Time appeared Maccms
Maccms maccms
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:maccms:maccms:*:*:*:*:*:*:*:*
Vendors & Products Maccms
Maccms maccms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-22T23:09:08.900Z

Reserved: 2026-03-22T08:20:15.860Z

Link: CVE-2026-4562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-23T00:16:51.647

Modified: 2026-03-23T00:16:51.647

Link: CVE-2026-4562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses