CVE-2020-15155Cross-site Scripting in Basercms

Severity
7.3HIGHNVD
EPSS
0.9%
top 24.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28

Description

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:NExploitability: 1.0 | Impact: 5.8

Affected Packages3 packages

CVEListV5baserproject/basercmsunspecified< 4.3.7
Packagistbaserproject/basercms4.0.04.3.7

Patches

🔴Vulnerability Details

2
GHSA
Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings2020-08-28
OSV
Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings2020-08-28