Access Restriction Bypass in baserCMS Potentially Exposes User Data
CVE-2018-0575

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 June 2018

What is CVE-2018-0575?

A security vulnerability in baserCMS allows remote attackers to bypass access restrictions in the mail form. This can lead to unauthorized access to files uploaded by site users, potentially exposing sensitive information. The vulnerability affects baserCMS versions 4.1.0.1 and earlier, as well as 3.0.15 and earlier versions. It is crucial for users and administrators to ensure their installations are up to date and to implement necessary security measures to mitigate this risk.

Affected Version(s)

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.