PT-2026-29152 · Basercms · Basercms

Kaminuma

·

Publicado

2026-03-31

·

Atualizado

2026-03-31

·

CVE-2026-30940

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions baserCMS versions prior to 5.2.3
Description baserCMS is a website development framework. A path traversal flaw exists in the theme file management API, specifically at the ''/baser/api/admin/bc-theme-file/theme files/add.json'' endpoint. An authenticated administrator can manipulate the path parameter using '..' sequences to create PHP files in locations outside the intended theme directory. This could lead to remote code execution (RCE). The vulnerable parameter is the path parameter.
Recommendations Update to version 5.2.3 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30940
GHSA-C5C6-37VQ-PJCQ

Produtos afetados

Basercms