Impact
MaxSite CMS up to version 109.6 is affected by a local file inclusion flaw that permits unauthenticated attackers to execute privileged handler files by supplying base64‑encoded path traversal sequences. The vulnerability bypasses existing path validation checks and allows execution of admin‑gated actions without authentication, potentially exposing sensitive functionality and data. This flaw qualifies as a remote code execution risk as attackers can run arbitrary code on the host system.
Affected Systems
The vulnerability affects the MaxSite CMS product from the vendor MaxSite. It is present in all releases up to and including version 109.6. No specific sub‑versions are listed beyond the major release. Users running any version of MaxSite CMS that has not been updated past 109.6 are impacted.
Risk and Exploitability
The CVSS score is 8.8, indicating a high likelihood of exploitation and significant impact if compromised. The EPSS score is not available, so the current exploitation probability cannot be estimated beyond the high CVSS rating. The vulnerability is not listed in the CISA KEV catalog, but attackers can still exploit it via HTTP requests to the ajax dispatcher endpoint. The likely attack vector involves sending a crafted request to the ajax endpoint with a base64‑encoded payload that contains a path traversal sequence; based on the description, it is inferred that the attacker submits the payload over an unauthenticated connection.
OpenCVE Enrichment