Skip to content

Security: maxsite/cms

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security issues in any way:

Supported only last version.


The MaxSite CMS administration panel is a fully trusted zone. It is strictly intended for the site owner and their trusted personnel only. Regular visitors and registered frontend users have no access to the admin panel.

Therefore:

  • Any reports regarding privilege escalation or capability bypasses within the admin panel will not be considered security vulnerabilities.
  • Executing PHP code, evaluating expressions via eval(), or editing files by authenticated administrators is intended core functionality (by design).
  • If a site owner does not fully trust a user, access to the admin panel must not be granted to that user.

Such reports will be closed as Won't fix / By design.

There aren't any published security advisories