CVE-2021-41243 – baserproject/basercms
Package
Manager: composer
Name: baserproject/basercms
Vulnerable Version: >=0 <4.5.4
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
EPSS: 0.02383 pctl0.84417
Details
OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS There is an OS Command Injection Vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible. Target baserCMS 4.5.3 and earlier versions Vulnerability OS Command Injection Vulnerability. Countermeasures Update to the latest version of baserCMS Credits Akagi Yusuke @NTT-ME
Metadata
Created: 2021-12-01T18:29:42Z
Modified: 2021-12-01T14:32:13Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7rpc-9m88-cf9w/GHSA-7rpc-9m88-cf9w.json
CWE IDs: ["CWE-78"]
Alternative ID: GHSA-7rpc-9m88-cf9w
Finding: F404
Auto approve: 1