Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33fq-qm4m-cjw3

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

baserCMS Access Control Bypass

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.

Пакеты

Наименование

baserproject/basercms

composer
Затронутые версииВерсия исправления

<= 3.0.15

3.0.16

Наименование

baserproject/basercms

composer
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.1.0.1

4.1.1

EPSS

Процентиль: 39%
0.00173
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.

EPSS

Процентиль: 39%
0.00173
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269