Описание
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
Ссылки
- Vendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 4.4.1 (исключая)
cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03225
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
CWE-434
Связанные уязвимости
CVSS3: 7.2
github
больше 5 лет назад
Edit template, Remote Code Execution (RCE) Vulnerability in Latest Release 4.4.0
EPSS
Процентиль: 87%
0.03225
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
CWE-434