CVE-2021-39136
HIGHbaserCMS < 4.5.1 - Stored Cross-Site Scripting via File Upload Function
Title source: llmDescription
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_confirm
https://github.com/baserproject/basercms/security/advisories/GHSA-hgjr-632x-qpp3
Patch, Third Party Advisory x_refsource_misc
https://github.com/baserproject/basercms/commit/568d4cab5ba1cdee7bbf0133c676d02a98f6d7bc
Vendor Advisory x_refsource_misc
https://basercms.net/security/JVN_14134801
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN14134801/index.html
Scores
CVSS v3
8.7
EPSS
0.0093
EPSS Percentile
56.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Details
CWE
CWE-79
Status
published
Products (2)
basercms/basercms
< 4.5.1
baserproject/basercms
0 - 4.5.1Packagist
Published
Aug 25, 2021
Tracked Since
Feb 18, 2026