Cross Site Scripting and RCE in baserCMS
Package
Affected versions
>= 4.0.0, <= 4.3.6
Patched versions
4.3.7
Description
Reviewed
Aug 28, 2020
Published to the GitHub Advisory Database
Aug 28, 2020
Last updated
Jan 9, 2023
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE).
Found by Vulnerability Research team in Flatt Security Inc.
References