CVE-2017-10844Code Injection in Basercms

CWE-94Code Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.6%
top 31.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 14

Description

baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDbasercms/basercms3.0.03.0.14+1
Packagistbaserproject/basercms4.0.04.0.5+1

Patches

🔴Vulnerability Details

2
OSV
Code Injection in baserCMS2022-05-14
GHSA
Code Injection in baserCMS2022-05-14