MEDIUM5.6
GHSA-77fc-4cv5-hmfr
baserCMS OS command injection vulnerability in Installer
Quick fix
GHSA-77fc-4cv5-hmfr — baserproject/basercms: upgrade to the fixed version with the command below.
composer require baserproject/basercms:^5.0.9Details
There is a OS command injection in Installer Feature to baserCMS.
### Target baserCMS 5.0.8 and earlier versions
### Vulnerability Malicious command may be executed in Installer.
### Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/baserproject/basercms
Introduced in:
0Fixed in: 5.0.9Fix
composer require baserproject/basercms:^5.0.9References
- https://github.com/baserproject/basercms/security/advisories/GHSA-77fc-4cv5-hmfr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-51450[ADVISORY]
- https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c[WEB]
- https://basercms.net/security/JVN_09767360[WEB]
- https://github.com/baserproject/basercms[PACKAGE]