PT-2026-29145 · Baserproject · Basercms

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2025-32957

CVSS v3.1

8.7

High

AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require once without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included. This issue has been patched in version 5.2.3.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-32957

Affected Products

Basercms