logo

CVE-2021-20681 baserproject/basercms

Package

Manager: composer
Name: baserproject/basercms
Vulnerable Version: >=0 <4.4.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00209 pctl0.43336

Details

Cross-site Scripting (XSS) in baserCMS Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

Metadata

Created: 2021-06-08T20:10:27Z
Modified: 2023-07-05T23:17:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-24p5-x9f9-vvpx/GHSA-24p5-x9f9-vvpx.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-24p5-x9f9-vvpx
Finding: F425
Auto approve: 1