CVE-2022-25412: Path Traversal
Published Feb 28, 2022
·Updated
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /adminpage/all-files-update-ajax.php via the dir and deletefile parameters.
Affected Software
1 affected component
Max-3000 Maxsite Cms=108
Remediation
Patch Available
Event History
Feb 28, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25412?
CVE-2022-25412 is a vulnerability found in Maxsite CMS v180 that allows arbitrary file deletion via the dir and deletefile parameters in /admin_page/all-files-update-ajax.php.
2
How severe is CVE-2022-25412?
CVE-2022-25412 has a severity rating of 8.1, which is considered high.
3
Which software versions are affected by CVE-2022-25412?
Maxsite CMS v180 is affected by CVE-2022-25412.
4
How can I fix CVE-2022-25412?
To fix CVE-2022-25412, it is recommended to update Maxsite CMS to a version that has addressed the vulnerability.
5
Where can I find more information about CVE-2022-25412?
More information about CVE-2022-25412 can be found on the Maxsite CMS GitHub page: https://github.com/maxsite/cms/issues/486.