Submit #762169: maxsite CMS CMS 109.1 Code Injection
Attacker-controlled input sent to the MarkItUp preview AJAX endpoint is passed through content hooks and reaches `eval()` in `run_php`, enabling ...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
