CVE-2022-39325

MEDIUM

Basercms < 4.7.2 - XSS

Title source: rule
STIX 2.1

Description

BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.

Scores

CVSS v3 4.6
EPSS 0.0069
EPSS Percentile 71.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
basercms/basercms < 4.7.2
baserproject/basercms 0 - 4.7.2Packagist
Published Nov 25, 2022
Tracked Since Feb 18, 2026