baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE).
- Impact: XSS to RCE via Arbitrary file upload.
- Attack vector is: Administrator must be logged in.
- Components are: ThemeFilesController.php, UploaderFilesController.php.
- Tested baserCMS Version : 4.3.6 (Latest)
- Affected baserCMS Version : 4.2.0 ~ 4.3.6 (XSS), 3.0.10 ~ 4.3.6 (RCE)
- Patches : https://basercms.net/security/20200827
Found by Vulnerability Research team in Flatt Security Inc.
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE).
Found by Vulnerability Research team in Flatt Security Inc.