MaxSite CMS
cpe:2.3:a:maxsite:cms:*:*:*:*:*:*:*
- <= 109.3
A cross-site scripting (XSS) vulnerability has been identified in MaxSite CMS versions prior to 109.3, specifically within the Redirect Plugin. The issue arises from the improper sanitization of user input in the 'f_all' and 'f_all404' arguments, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely and is now public knowledge.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, upload a script to a server running MaxSite CMS version 109.3 or earlier. Then, use the Redirect Plugin to create a redirect that includes the 'f_all' or 'f_all404' arguments. The injected script will be executed when the redirect is accessed.
Users are advised to upgrade to MaxSite CMS version 109.4 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.