logo

CVE-2021-20683 baserproject/basercms

Package

Manager: composer
Name: baserproject/basercms
Vulnerable Version: >=0 <4.4.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00209 pctl0.43336

Details

Cross-site Scripting (XSS) in baserCMS Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

Metadata

Created: 2021-06-08T20:10:45Z
Modified: 2021-03-29T22:34:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-v9w8-hq92-v39m/GHSA-v9w8-hq92-v39m.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-v9w8-hq92-v39m
Finding: F425
Auto approve: 1