CVE-2011-2674Improper Privilege Management in Basercms

Severity
4.9MEDIUMNVD
EPSS
0.2%
top 58.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 13

Description

BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9

Affected Packages2 packages

Packagistbaserproject/basercms< 1.6.12
NVDbasercms/basercms1.6.11.4+23

🔴Vulnerability Details

2
GHSA
BaserCMS privilege escallation2022-05-13
OSV
BaserCMS privilege escallation2022-05-13

💬Community

1
Bugzilla
CVE-2011-1412 CVE-2011-2764 CVE-2011-3012 quake3: arbitrary code execution vulnerabilites in ioquake32011-07-27