{"id":"CVE-2026-70554","published":"2026-08-04T21:16:38.613","lastModified":"2026-08-05T15:17:13.783","description":"MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://github.com/maxsite/cms","tags":[]},{"url":"https://max-3000.com/page/maxsite-cms-109-6","tags":[]},{"url":"https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-php-object-injection-via-maxsite-comuser-cookie","tags":[]}],"exploitRefs":[{"url":"https://github.com/maxsite/cms","tags":[]}],"hasPoc":true,"ai":{"summary":"MaxSite CMS is vulnerable to PHP object injection, allowing unauthenticated attackers to execute arbitrary code via a malicious serialized PHP object in the maxsite_comuser cookie.","exploitability":"Exploitation is relatively straightforward as attackers can craft a payload in a single HTTP request, but requires the attacker to have control over the cookie value.","blast_radius":"If exploited, this vulnerability could result in full remote code execution on the affected server, potentially leading to data theft, service disruption, or complete compromise of the system.","remediation":"Disable the affected feature or restrict access to the maxsite_comuser cookie to prevent unauthenticated attackers from injecting PHP objects.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","cookie","php","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:01:24.010Z"}}