Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxg4-xmxc-6qm6

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

EPSS

Процентиль: 27%
0.00337
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 8.2
nvd
15 дней назад

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

EPSS

Процентиль: 27%
0.00337
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-98