Remote File Deletion Vulnerability in baserCMS by baserCMS
CVE-2017-10843

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
29 August 2017

What is CVE-2017-10843?

In baserCMS versions 3.0.14 and earlier, as well as 4.0.5 and earlier, a vulnerability exists that allows remote attackers to delete arbitrary files through unspecified vectors during the use of the 'File' field in the mail form. This potential exploit could lead to unauthorized file manipulations, posing a risk to the integrity and security of the affected web applications.

Affected Version(s)

baserCMS 3.0.14 and earlier

baserCMS 4.0.5 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.