Executive brief
MaxSite CMS is a content management system for websites and blogs. An attacker can forge administrator session cookies without credentials because the application uses a hardcoded, publicly known encryption key that is never changed during installation. This allows an unauthenticated attacker to gain full administrative access to any MaxSite CMS instance.
Technical details
The vulnerability combines three defects: (1) the session encryption key is hardcoded as 'encryption key' in application/config/config.php and never changed by the installer, (2) sessions are stored in ci_session cookies as PHP-serialized data signed with only HMAC-SHA1 using the public key, allowing attackers to forge cookies with arbitrary contents like userlogged=1 and users_groups_id=1, and (3) the database re-validation in init.php passes malformed ciphertext (which decrypts to boolean false) directly to database queries, causing MySQL to match the administrator row. An unauthenticated network attacker can forge a valid administrator session cookie and access the admin panel without any credentials. Versions 109.6 and earlier using CodeIgniter 2.x session handling are affected.
Affected products
- MaxSite CMS through 109.6
Timeline
- 2026-09-09: disclosed
- 2026-09-08: other: Advisory published on GitHub