PT-2025-44083 · Unknown · Maxsite Cms

V3Ged4G

·

Published

2025-10-28

·

Updated

2025-10-28

·

CVE-2025-12347

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaxSite CMS versions prior to 110
Description A flaw exists in MaxSite CMS that allows for unrestricted file uploads. This issue is related to the processing of the file path and content arguments within the file application/maxsite/admin/plugins/editor files/save-file-ajax.php. The attack can be carried out remotely. The exploit for this issue has been published.
Recommendations Update MaxSite CMS to version 110 or later.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12347

Affected Products

Maxsite Cms