JavaScript Injection Vulnerability in baserCMS by baserCMS Team
CVE-2021-20681

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 March 2021

What is CVE-2021-20681?

A vulnerability in the page editing function of baserCMS allows remote authenticated attackers to insert arbitrary JavaScript code by exploiting improper input neutralization. This flaw could potentially lead to unauthorized actions or data exposure, posing significant security risks for systems running vulnerable versions. Users are advised to upgrade to baserCMS version 4.4.5 or later to mitigate these risks.

Affected Version(s)

baserCMS versions prior to 4.4.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.