Description
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.
References (3)
Core 3
Core References
Vendor Advisory
https://basercms.net/security/JVN_53682526
Patch, Third Party Advisory
https://github.com/baserproject/basercms/commit/b6f8a54e90dee51317eddf517b776fe8b4cd3ef6
Third Party Advisory
https://github.com/baserproject/basercms/security/advisories/GHSA-395x-wv32-44v5
Scores
CVSS v3
4.6
EPSS
0.0069
EPSS Percentile
71.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
basercms/basercms
< 4.7.2
baserproject/basercms
0 - 4.7.2Packagist
Published
Nov 25, 2022
Tracked Since
Feb 18, 2026