Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings
Package
Affected versions
>= 4.0.0, <= 4.3.6
Patched versions
4.3.7
Description
Reviewed
Aug 28, 2020
Published to the GitHub Advisory Database
Aug 28, 2020
Last updated
Jan 9, 2023
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
References