Executive brief
MaxSite CMS is a website content management system that handles requests through dispatcher files. The vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files by supplying specially crafted base64-encoded path traversal sequences, bypassing validation checks that are meant to restrict file access. This can lead to unauthorized code execution and exposure of sensitive administrative functionality.
Technical details
This is a local file inclusion (LFI) vulnerability in the ajax and require-maxsite dispatchers (application/views/ajax.php and application/views/require-maxsite.php). The root cause is a flawed path validation check: the code constructs a file path by concatenating base_dir with a base64-decoded attacker-controlled URI segment, then uses a substring check (strpos) to validate containment. Because the attacker input is appended to base_dir, the resulting path always contains base_dir as a leading substring even when the input contains ../ sequences that escape the intended directory. An unauthenticated attacker can send a request to /ajax/<base64-encoded-path> with a path traversal payload to include arbitrary files ending in -ajax.php or -require-maxsite.php. Included files are executed as PHP, potentially allowing code execution if a writable handler file is reached. The fix requires replacing the substring check with canonical path resolution (realpath) and explicitly rejecting .. sequences or maintaining an allowlist of permitted handlers.
Affected products
- MaxSite CMS through 109.6
Timeline
- 2026-09-09: disclosed