baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/baserproject/basercms/security/advisories/GHSA-6fmv-q269-55cw | third party advisory patch |
https://basercms.net/security/20201029 | vendor advisory |
https://github.com/baserproject/basercms/commit/bb027c3967b0430adcff2d2fedbc23d39077563b | third party advisory patch |