Page 4 of 17 results (0.002 seconds)

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en la configuración de permisos de las versiones de baserCMS anteriores a la 4.7.2 permite a un atacante remoto autenticado con privilegios administrativos inyectar un script arbitrario. • https://basercms.net/security/JVN_53682526 https://jvn.jp/en/jp/JVN53682526/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability. • https://basercms.net/security/JVN_53682526 https://github.com/baserproject/basercms/commit/b6f8a54e90dee51317eddf517b776fe8b4cd3ef6 https://github.com/baserproject/basercms/security/advisories/GHSA-395x-wv32-44v5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •