CVE-2021-39136

HIGH

baserCMS < 4.5.1 - Stored Cross-Site Scripting via File Upload Function

Title source: llm
STIX 2.1

Description

baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
https://basercms.net/security/JVN_14134801
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN14134801/index.html

Scores

CVSS v3 8.7
EPSS 0.0093
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-79
Status published
Products (2)
basercms/basercms < 4.5.1
baserproject/basercms 0 - 4.5.1Packagist
Published Aug 25, 2021
Tracked Since Feb 18, 2026