Metrics
Affected Vendors & Products
Tue, 28 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maxsite
Maxsite cms |
|
| Vendors & Products |
Maxsite
Maxsite cms |
Tue, 28 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | MaxSite CMS save-file-ajax.php unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-28T02:02:13.123Z
Updated: 2025-10-28T20:00:38.998Z
Reserved: 2025-10-27T14:13:59.258Z
Link: CVE-2025-12347
Updated: 2025-10-28T20:00:22.021Z
Status : Received
Published: 2025-10-28T03:15:34.117
Modified: 2025-10-28T03:15:34.117
Link: CVE-2025-12347
No data.