MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 17:17
Updated : 2026-09-09 20:14
NVD link : CVE-2026-87930
Mitre link : CVE-2026-87930
CVE.ORG link : CVE-2026-87930
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
