basercms.net
https://basercms.net/security/JVN_45547161 CVE-2023-43792
CRITICAL
baserCMS Code Injection Vulnerability in Mail Form Feature
Record summary
CVE-2023-43792 has a selected CVSS score of 9.8 (critical).
Description
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
basercmsBrowse baserproject / basercms | CVE List | >= 4.6.0, <= 4.7.6 | affected |
baserproject/basercmsBrowse Packagist / baserproject/basercms | GitHub Advisory | 4.6.0 to ≤ 4.7.6 | affected |
References
4github.com
https://github.com/baserproject/basercms github.comConfirmation
https://github.com/baserproject/basercms/security/advisories/GHSA-vrm6-c878-fpq6 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-43792