CVE-2020-15159 Information
Feb 14, 2021
cve
Description
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and UploaderFilesController.php. This is fixed in version 4.3.7.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Reference
https://basercms.net/security/20200827 https://github.com/baserproject/basercms/commit/16a7b3cd09a0ca355474119c76897eac2034a66d https://github.com/baserproject/basercms/security/advisories/GHSA-673x-f5wx-fxpw
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.6
Share on: