Unrestricted File Upload Vulnerability in MaxSite CMS by MaxSite
CVE-2025-12347
Key Information:
Badges
What is CVE-2025-12347?
A vulnerability has been identified in MaxSite CMS versions up to 109 that allows an attacker to execute remote exploitation through the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. By manipulating the file_path/content argument, an attacker can perform unrestricted file uploads onto the server. This may lead to various malicious actions, including the potential execution of arbitrary code and unauthorized access to sensitive information. Despite early notification to the vendor regarding this flaw, there has been no response, elevating concerns over user security and the necessity for immediate action.
Affected Version(s)
CMS 109
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
