CVE-2021-20683 – baserproject/basercms
Package
Manager: composer
Name: baserproject/basercms
Vulnerable Version: >=0 <4.4.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00209 pctl0.43336
Details
Cross-site Scripting (XSS) in baserCMS Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
Metadata
Created: 2021-06-08T20:10:45Z
Modified: 2021-03-29T22:34:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-v9w8-hq92-v39m/GHSA-v9w8-hq92-v39m.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-v9w8-hq92-v39m
Finding: F425
Auto approve: 1