7.6
CVE-2020-15159
- EPSS 2.15%
- Veröffentlicht 28.08.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:58
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Cross Site Scripting leading to RCE in baserCMS
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and UploaderFilesController.php. This is fixed in version 4.3.7.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.15% | 0.798 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 1 | 6 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:N/AC:H/Au:S/C:P/I:P/A:P
|
| security-advisories@github.com | 7.6 | 1 | 6 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://basercms.net/security/20200827
https://github.com/baserproject/basercms/commit/16a7b3cd09a0ca355474119c76897eac2034a66d
https://github.com/baserproject/basercms/security/advisories/GHSA-673x-f5wx-fxpw