GHSA-hv78-cwp4-8r7r
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
Quick fix
GHSA-hv78-cwp4-8r7r — baserproject/basercms: upgrade to the fixed version with the command below.
composer require baserproject/basercms:^5.2.3Details
### Details The application's restore function allows users to upload a `.zip` file, which is then automatically extracted. A PHP file inside the archive is included using `require_once` without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included.
Vector: Malicious ZIP upload + insecure `require_once`
### PoC 1. Restore backup  1. Load file shell (insecure `require_once`)  
### Impact Remote Code Execution (RCE)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 5.2.3composer require baserproject/basercms:^5.2.3References
- https://github.com/baserproject/basercms/security/advisories/GHSA-hv78-cwp4-8r7r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-32957[ADVISORY]
- https://basercms.net/security/JVN_20837860[WEB]
- https://github.com/baserproject/basercms[PACKAGE]
- https://github.com/baserproject/basercms/releases/tag/5.2.3[WEB]