Описание
baserCMS OS command injection vulnerability in Installer
There is a OS command injection in Installer Feature to baserCMS.
Target
baserCMS 5.0.8 and earlier versions
Vulnerability
Malicious command may be executed in Installer.
Countermeasures
Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159
Пакеты
baserproject/basercms
< 5.0.9
5.0.9
Связанные уязвимости
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
Уязвимость CMS-системы BaserCMS, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды