Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings
Low
baserproject
published
GHSA-4r3m-j6x5-48m3Aug 27, 2020
Package
No package listed
Affected versions
4.3.6
Patched versions
4.3.7
Description
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS).
Impact: XSS via Arbitrary script execution.
Attack vector is: Administrator must be logged in.
Components are: toolbar.php
Tested baserCMS Version : 4.3.6 (Latest)
Affected baserCMS Version : 4.0.0 ~ 4.3.6
Patches : https://basercms.net/security/20200827
Found by Aquilao Null
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS).
Impact: XSS via Arbitrary script execution.
Attack vector is: Administrator must be logged in.
Components are: toolbar.php
Tested baserCMS Version : 4.3.6 (Latest)
Affected baserCMS Version : 4.0.0 ~ 4.3.6
Patches : https://basercms.net/security/20200827
Found by Aquilao Null