CVE-2021-20681 – baserproject/basercms
Package
Manager: composer
Name: baserproject/basercms
Vulnerable Version: >=0 <4.4.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00209 pctl0.43336
Details
Cross-site Scripting (XSS) in baserCMS Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
Metadata
Created: 2021-06-08T20:10:27Z
Modified: 2023-07-05T23:17:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-24p5-x9f9-vvpx/GHSA-24p5-x9f9-vvpx.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-24p5-x9f9-vvpx
Finding: F425
Auto approve: 1