VDB
Sign up
MEDIUM

GHSA-jmq3-x8q7-j9qm

baserCMS has a cross-site scripting vulnerability in blog posts

Quick fix

GHSA-jmq3-x8q7-j9qm — baserproject/basercms: upgrade to the fixed version with the command below.

composer require baserproject/basercms:^5.2.3

Details

baserCMS has a cross-site scripting vulnerability in blog posts.

### Target baserCMS 5.2.1 and earlier versions

### Vulnerability

Malicious Javascript may be executed in blog posts.

### Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860

### Credits

Gai Tanaka@Mitsui Bussan Secure Directions, Inc.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/baserproject/basercms
Introduced in: 0Fixed in: 5.2.3
Fixcomposer require baserproject/basercms:^5.2.3

References