MaxSite CMS(版本 109.6 及之前)在 中内置了一个硬编码的会话加密密钥,该密钥在安装过程中从未被修改。这允许未经身份验证的攻击者伪造管理员会话 Cookie。 攻击者可以使用公开的加密密钥,通过计算 HMAC-SHA1 哈希值,生成一个具有管理员权限的恶意 Cookie,从而绕过 和 函数中的身份验证检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MaxSite | MaxSite CMS | 0.78 ~ 109.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87927 | 8.2 HIGH | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher |
| CVE-2026-87930 | 8.1 HIGH | MaxSite CMS through 109.6 PHP Object Injection via ci_session |
| CVE-2026-87928 | 5.4 MEDIUM | MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page |
No comments yet