Unrestricted File Upload Vulnerability in MaxSite CMS Software
CVE-2025-12346
Key Information:
Badges
What is CVE-2025-12346?
A severe vulnerability in MaxSite CMS versions up to 109 allows attackers to exploit the HTTP Header Handler component through manipulation of the X-Requested-FileName and X-Requested-FileUpDir parameters. This flaw enables unauthorized file uploads, resulting in arbitrary remote file execution and potential server compromise. The exploit has been made public, raising significant risks for users of the affected versions. Early attempts to contact the vendor regarding this issue went unanswered, highlighting the urgency of addressing this security gap.
Affected Version(s)
CMS 109
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
