{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/maxsite-cms-105.2---109.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-70553"},{"cvss":9.8,"id":"CVE-2026-70554"},{"cvss":9.8,"id":"CVE-2026-70552"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=2FCD7081-4746-5C48-84DA-7F1228A2481C\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["MaxSite CMS","MaxSite CMS (109.5)","MaxSite CMS (105.2 - 109.5)"],"_cs_severities":["critical"],"_cs_tags":["web-application","cms","vulnerability"],"_cs_type":"advisory","_cs_vendors":["MaxSite"],"content_html":"\u003cp\u003eMaxSite CMS contains a critical remote code execution vulnerability (CVE-2026-70553) affecting the application's installation process. An unauthenticated attacker can exploit this flaw by submitting crafted POST requests to the CMS installation endpoint, even after the initial installation is complete. By providing a specifically crafted 'db_dbprefix' parameter containing a single quote, an attacker can break out of the PHP string literal within 'application/config/database.php'. This allows for the injection and subsequent execution of arbitrary PHP code. The injected payload is written to the configuration file and is executed by the web server process during every subsequent application request, granting the attacker persistent code execution capabilities with the privileges of the web service account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full server-side compromise, as the attacker achieves unauthenticated remote code execution. This allows for data exfiltration, lateral movement within the network, or complete takeover of the affected web application. This vulnerability poses a severe risk to any organization running an exposed MaxSite CMS instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch MaxSite CMS to the latest version provided by the vendor to address the improper input sanitization in the installation module.\u003c/li\u003e\n\u003cli\u003eReview the 'application/config/database.php' file for any anomalous PHP code or unexpected modifications to the 'db_dbprefix' variable.\u003c/li\u003e\n\u003cli\u003eRestrict access to the CMS installation endpoint (e.g., /install) via web application firewall or server configuration rules after the initial site setup is complete.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests targeting installation directories that occur outside of documented deployment windows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T16:38:57Z","date_published":"2026-08-04T22:02:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-maxsite-cms-rce/","summary":"MaxSite CMS is vulnerable to remote code execution due to improper input sanitization of the db_dbprefix parameter, allowing unauthenticated attackers to inject persistent PHP code into the database configuration file.","title":"Unauthenticated Remote Code Execution in MaxSite CMS via Config Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-maxsite-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - MaxSite CMS (105.2 - 109.5)","version":"https://jsonfeed.org/version/1.1"}