Page 3 of 40 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0. baserCMS es un framework de desarrollo de sitios web con WebAPI que se ejecuta en PHP8 y CakePHP4. Existe una vulnerabilidad XSS en Favorites Feature de baserCMS. Este problema se solucionó en la versión 4.8.0. • https://basercms.net/security/JVN_45547161 https://github.com/baserproject/basercms/releases/tag/basercms-4.8.0 https://github.com/baserproject/basercms/security/advisories/GHSA-8vqx-prq4-rqrq • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch. • https://github.com/baserproject/basercms/commit/922025a98b0e697ab78f6a785a004e0729aa9100 https://github.com/baserproject/basercms/commit/9297629983ed908c7f51bf61a0231dde91404ebd https://github.com/baserproject/basercms/releases/tag/basercms-4.7.5 https://github.com/baserproject/basercms/security/advisories/GHSA-mfvg-qwcw-qvc8 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 0

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch. • https://github.com/baserproject/basercms/commit/002886be0998c74c386e04f0b43688a8a45d7a96 https://github.com/baserproject/basercms/commit/08247f0a633d8e836ce2e5cd2d53aa19901a1359 https://github.com/baserproject/basercms/commit/60f83054d8131b0ace60716cec7e629b5eb3a8f0 https://github.com/baserproject/basercms/releases/tag/basercms-4.7.5 https://github.com/baserproject/basercms/security/advisories/GHSA-h4cc-fxpp-pgw9 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en la gestión de grupos de usuarios de versiones de baserCMS anteriores a la 4.7.2 permite a un atacante remoto autenticado con privilegios administrativos inyectar un script arbitrario. • https://basercms.net/security/JVN_53682526 https://jvn.jp/en/jp/JVN53682526/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en la configuración de permisos de las versiones de baserCMS anteriores a la 4.7.2 permite a un atacante remoto autenticado con privilegios administrativos inyectar un script arbitrario. • https://basercms.net/security/JVN_53682526 https://jvn.jp/en/jp/JVN53682526/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •