VDB
Sign up
HIGH7.1

GHSA-677c-xv24-crgx

baserCMS is Vulnerable to Cross-site Scripting

Quick fix

GHSA-677c-xv24-crgx — baserproject/basercms: upgrade to the fixed version with the command below.

composer require baserproject/basercms:^5.2.3

Details

baserCMS has DOM-based cross-site scripting in tag creation.

### Target baserCMS 5.2.2 and earlier versions

### Vulnerability Malicious JavaScript may be executed when creating a tag.

### Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030

### Credits

- quanlna2 (Le Nguyen Anh Quan) - namdi (Do Ich Nam) - minhnn42 (Nguyen Ngoc Minh) - VCSLab - Viettel Cyber Security

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/baserproject/basercms
Introduced in: 0Fixed in: 5.2.3
Fixcomposer require baserproject/basercms:^5.2.3

References