JVN#67881316Third-party advisory
http://jvn.jp/en/jp/JVN67881316/index.html CVE-2018-0573
MEDIUM
baserCMS Access Control Bypass
Record summary
CVE-2018-0573 has a selected CVSS score of 5.3 (medium).
Description
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) | affected | |
baserproject/basercmsBrowse Packagist / baserproject/basercms | GitHub Advisory | Before 3.0.16 · Fixed in 3.0.16 | affected |
| 4.0.0 to < 4.1.1 · Fixed in 4.1.1 | affected |
References
3basercms.net
https://basercms.net/security/JVN67881316 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0573