There is a Code Injection Vulnerability in Mail Form to baserCMS.
baserCMS 4.7.6 and earlier versions
Malicious code may be executed in Mail Form Feature.
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_45547161
Shiga Takuma@BroadBand Security, Inc
| Score | Percentile |
|---|---|
| 0.34% | 56.51% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.3 | 3.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-vrm6-c878-fpq6 ↗ |
| CVE | CVE-2023-43792 ↗ |
| CWE id | Name |
|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | baserproject/basercms | >= 4.6.0, <= 4.7.6 | — | — |