漏洞描述
MaxSite CMS through 109.1 allows unauthenticated remote attackers to execute arbitrary code via the MarkItUp editor preview AJAX endpoint, preview-ajax.php. The endpoint insufficiently authenticates the request, failing to ensure the user is logged in, and processes the attacker's input via unsafe usage of PHP eval() on user-supplied [php]...[/php] shortcodes. By providing a POST request to the vulnerable /ajax/ endpoint with crafted input, attackers may achieve remote code execution. The issue is addressed in version 109.2 by implementing proper authentication controls.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/mbanyamer/CVE-2026-3395-MaxSite-CMS-Unauthenticated-RCE↗github.comhttps://github.com/rootdirective-sec/CVE-2026-3395-Lab↗github.comhttps://github.com/maxsite/cms/commit/08937a3c5d672a242d68f53e9fccf8a748820ef3↗vuldb.comhttps://vuldb.com/?id.348281↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-3395↗