CVE-2022-25411: Malicious File Upload
Published Feb 28, 2022
·Updated
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
1 affected component
Max-3000 Maxsite Cms=108
Event History
Feb 28, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25411?
CVE-2022-25411 is a Remote Code Execution vulnerability in Maxsite CMS v180 that allows attackers to execute arbitrary code via a crafted PHP file.
2
How severe is CVE-2022-25411?
CVE-2022-25411 has a severity rating of 9.8 (critical).
3
How does CVE-2022-25411 affect Maxsite CMS?
CVE-2022-25411 affects Maxsite CMS v180.
4
How can the CVE-2022-25411 vulnerability be exploited?
CVE-2022-25411 can be exploited by attackers by sending a specially crafted PHP file to /admin/options in Maxsite CMS v180.
5
Is there a fix available for CVE-2022-25411?
It is recommended to update to a patched version of Maxsite CMS to fix the CVE-2022-25411 vulnerability.