Impact
The flaw allows a logged‑in user to upload arbitrary HTML files to the uploads/_pages/ directory. When visitors load these files the embedded scripts run with the visitor’s privileges, producing a persistent stored cross‑site scripting (XSS) condition. This can lead to credential theft, defacement or drive‑by‑attack actions from the compromised site.
Affected Systems
MaxSite CMS versions 0.94 through 109.6 are affected. The vulnerability is limited to installations where the admin_page upload handler is enabled and accessible to authenticated users.
Risk and Exploitability
With a CVSS score of 5.1 the vulnerability is of moderate severity. No EPSS score is reported, so the relative likelihood of exploitation is unknown, but the flaw requires authentication, meaning exposure depends on the presence of logged‑in users. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no known widespread exploitation.
OpenCVE Enrichment