CVE-2020-15159
- EPSS 2.15%
- Veröffentlicht 28.08.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:58
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ...
CVE-2020-15155
- EPSS 1.29%
- Veröffentlicht 28.08.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:57
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
CVE-2020-15154
- EPSS 1.01%
- Veröffentlicht 28.08.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:04:57
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, conte...
CVE-2018-18942
- EPSS 2.4%
- Veröffentlicht 05.11.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:55
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
CVE-2018-18943
- EPSS 0.73%
- Veröffentlicht 05.11.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:55
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.
CVE-2018-0575
- EPSS 1.18%
- Veröffentlicht 26.06.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:30
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.
CVE-2018-0574
- EPSS 0.84%
- Veröffentlicht 26.06.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:30
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0573
- EPSS 1.12%
- Veröffentlicht 26.06.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:30
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.
CVE-2018-0572
- EPSS 1.63%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:30
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors.
CVE-2018-0571
- EPSS 1.13%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:30
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.