baserCMS Fixes Cross-Site Scripting Vulnerability in Site Search Feature
CVE-2023-44379

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 February 2024

What is CVE-2023-44379?

The baserCMS framework, utilized for website development, has a cross-site scripting vulnerability in its site search functionality prior to version 5.0.9. This security flaw can potentially be exploited by attackers to inject malicious scripts into web pages viewed by users, thereby compromising the integrity and security of the affected website. Version 5.0.9 addresses this issue, making it imperative for users to update to this release to mitigate the risk of exploitation.

Affected Version(s)

basercms < 5.0.9

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.