Описание
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Ссылки
- Vendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.8.0 (исключая)
cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00107
Низкий
4.7 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.7
github
больше 2 лет назад
baserCMS CSRF vulnerability in Content preview Feature
EPSS
Процентиль: 29%
0.00107
Низкий
4.7 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-352