There is a OS command injection in Installer Feature to baserCMS.
baserCMS 5.0.8 and earlier versions
Malicious command may be executed in Installer.
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_73283159
| Score | Percentile |
|---|---|
| 0.76% | 72.97% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.6 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-77fc-4cv5-hmfr ↗ |
| CVE | CVE-2023-51450 ↗ |
| CWE id | Name |
|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | baserproject/basercms | < 5.0.9 | 5.0.9 | — |