Maybecms · Maybecms · CVE-2025-0871
**Name of the Vulnerable Software and Affected Versions**
Maybecms version 1.2
**Description**
A problematic issue has been found in Maybecms, affecting an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. The manipulation of the `data info[content]` argument leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
**Recommendations**
For Maybecms version 1.2, as a temporary workaround, consider restricting access to the /mb/admin/index.php?u=article-edit endpoint until a patch is available. Avoid using the `data info[content]` argument in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.