VDB
Sign up
HIGH8.7

GHSA-hv78-cwp4-8r7r

baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)

Quick fix

GHSA-hv78-cwp4-8r7r — baserproject/basercms: upgrade to the fixed version with the command below.

composer require baserproject/basercms:^5.2.3

Details

### Details The application's restore function allows users to upload a `.zip` file, which is then automatically extracted. A PHP file inside the archive is included using `require_once` without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included.

Vector: Malicious ZIP upload + insecure `require_once`

### PoC 1. Restore backup ![image](https://github.com/user-attachments/assets/9e59768a-4a8e-472d-aaef-5d54546080f6) 1. Load file shell (insecure `require_once`) ![image](https://github.com/user-attachments/assets/8f7919a2-c7f3-4ae1-af6c-1b0057e4ba22) ![image](https://github.com/user-attachments/assets/c10ef049-459d-429e-a608-8fb220c3387f)

### Impact Remote Code Execution (RCE)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/baserproject/basercms
Introduced in: 0Fixed in: 5.2.3
Fixcomposer require baserproject/basercms:^5.2.3

References