Skip to content

Cross Site Scripting and RCE in baserCMS

Low severity GitHub Reviewed Published Aug 27, 2020 in baserproject/basercms • Updated Jan 9, 2023

Package

composer baserproject/basercms (Composer)

Affected versions

>= 4.0.0, <= 4.3.6

Patched versions

4.3.7

Description

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE).

  • Impact: XSS to RCE via Arbitrary file upload.
  • Attack vector is: Administrator must be logged in.
  • Components are: ThemeFilesController.php, UploaderFilesController.php.
  • Tested baserCMS Version : 4.3.6 (Latest)
  • Affected baserCMS Version : 4.2.0 ~ 4.3.6 (XSS), 3.0.10 ~ 4.3.6 (RCE)
  • Patches : https://basercms.net/security/20200827

Found by Vulnerability Research team in Flatt Security Inc.

References

@baserproject baserproject published to baserproject/basercms Aug 27, 2020
Reviewed Aug 28, 2020
Published to the GitHub Advisory Database Aug 28, 2020
Last updated Jan 9, 2023

Severity

Low

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(78th percentile)

Weaknesses

CVE ID

CVE-2020-15159

GHSA ID

GHSA-673x-f5wx-fxpw

Source code

No known source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.