Cross-Site Scripting Vulnerability in baserCMS by baserCMS, Inc.
CVE-2018-0574

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 June 2018

What is CVE-2018-0574?

A cross-site scripting vulnerability exists in baserCMS versions 4.1.0.1 and earlier, as well as 3.0.15 and earlier. This security issue allows remote attackers to inject arbitrary web scripts or HTML into the application through unspecified vectors, potentially compromising user data and session integrity. It is critical for users of affected versions to apply the recommended security updates to mitigate this risk.

Affected Version(s)

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.