CVE-2022-39325

MEDIUM

basercms < 4.7.2 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.

Scores

CVSS v3 4.6
EPSS 0.0055
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
basercms/basercms < 4.7.2
baserproject/basercms 0 - 4.7.2Packagist
Published Nov 25, 2022
Tracked Since Feb 18, 2026