Please report security issues in any way:
- Email: maxsite.org@gmail.com
- Telegram: https://t.me/maxsite_org
- https://github.com/maxsite/cms/issues
Supported only last version.
The MaxSite CMS administration panel is a fully trusted zone. It is strictly intended for the site owner and their trusted personnel only. Regular visitors and registered frontend users have no access to the admin panel.
Therefore:
- Any reports regarding privilege escalation or capability bypasses within the admin panel will not be considered security vulnerabilities.
- Executing PHP code, evaluating expressions via eval(), or editing files by authenticated administrators is intended core functionality (by design).
- If a site owner does not fully trust a user, access to the admin panel must not be granted to that user.
Such reports will be closed as Won't fix / By design.