Executive brief
MaxSite CMS is a free content management system used to build websites and blogs. The system contains a critical vulnerability in how it processes user cookies, allowing attackers to send malicious data that executes arbitrary code on the server without needing to log in. A single malicious HTTP request can compromise the entire website and potentially expose all customer data.
Technical details
The vulnerability is a PHP object injection (insecure deserialization) flaw in the maxsite_comuser cookie handling. User-controlled serialized data from the cookie is passed directly to unserialize() without validation or class allowlisting, enabling object instantiation and gadget chain exploitation. No authentication is required—the attack vector is network-based via a single HTTP request. Attackers can craft malicious serialized PHP objects targeting gadget chains in available extensions (e.g., SoapClient, Imagick) to achieve remote code execution. A patch is available in version 109.6; versions 109.5 and below are vulnerable.
Affected products
- MaxSite MaxSite CMS 109.5 and below
Timeline
- 2026-08-04: disclosed
- 2026-06-08: patched: Critical security fixes applied in version 109.6