PT-2020-14235 · Basercms · Basercms

Stypr

·

Published

2020-08-28

·

Updated

2020-09-03

·

CVE-2020-15159

CVSS v3.1

7.6

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions baserCMS versions 4.3.6 and earlier baserCMS versions 4.2.0 through 4.3.6 baserCMS versions 3.0.10 through 4.3.6
Description The issue affects baserCMS, allowing for Cross Site Scripting (XSS) and Remote Code Execution (RCE) due to arbitrary file upload. This can be executed by logging in as a system administrator and uploading an executable script file, such as a PHP file. The affected components are ThemeFilesController.php and UploaderFilesController.php.
Recommendations For versions 4.3.6 and earlier, update to version 4.3.7 to resolve the issue. For versions 4.2.0 through 4.3.6, update to version 4.3.7 to mitigate the XSS risk. For versions 3.0.10 through 4.3.6, update to version 4.3.7 to mitigate the RCE risk. As a temporary workaround, consider restricting access to the ThemeFilesController.php and UploaderFilesController.php components until a patch is applied. Avoid uploading executable script files, such as PHP files, to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15159
GHSA-673X-F5WX-FXPW

Affected Products

Basercms