PHP Object Injection Vulnerability in MaxSite CMS by MaxSite
CVE-2026-70554
What is CVE-2026-70554?
MaxSite CMS has a PHP object injection vulnerability that poses a significant risk to users. Unauthenticated attackers can exploit this flaw by injecting crafted serialized data into the 'maxsite_comuser' cookie, which is then passed to the unserialize() function without proper validation or class allowlisting. This oversight allows attackers to invoke magic methods during the deserialization process, facilitating property-oriented programming attacks or enabling remote code execution through various gadget chains, particularly those associated with the SoapClient or Imagick extensions. It is crucial for organizations using MaxSite CMS to apply the necessary patches and mitigate potential threats.
Affected Version(s)
MaxSite CMS 0.78 <= 109.5
MaxSite CMS 0.78 <= 109.5
MaxSite CMS 109.6
