CVE-2025-12346

Source
https://cve.org/CVERecord?id=CVE-2025-12346
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12346.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12346
Published
2025-10-28T03:15:33.917Z
Modified
2026-03-14T15:01:49.371039Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument X-Requested-FileName/X-Requested-FileUpDir results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git / github.com/maxsite/cms

Affected ranges

Type
GIT
Repo
https://github.com/maxsite/cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "109"
        }
    ]
}

Affected versions

v0.*
v0.87
v0.87.1
v0.88
v0.89
v0.90
v0.91
v0.92
v0.93
v0.94
v0.95
v0.96
Other
v100
v101
v102
v104
v106
v107
v108
v109
v97
v98
v99

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12346.json"