Headline
GHSA-77fc-4cv5-hmfr: baserCMS OS command injection vulnerability in Installer
There is a OS command injection in Installer Feature to baserCMS.
Target
baserCMS 5.0.8 and earlier versions
Vulnerability
Malicious command may be executed in Installer.
Countermeasures
Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159
Package
composer baserproject/basercms (Composer)
Affected versions
< 5.0.9
Patched versions
5.0.9
Description
There is a OS command injection in Installer Feature to baserCMS.
Target
baserCMS 5.0.8 and earlier versions
Vulnerability
Malicious command may be executed in Installer.
Countermeasures
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_73283159
References
- GHSA-77fc-4cv5-hmfr
- https://nvd.nist.gov/vuln/detail/CVE-2023-51450
- baserproject/basercms@18f426d
- https://basercms.net/security/JVN_09767360
ryuring published to baserproject/basercms
Feb 22, 2024
Published by the National Vulnerability Database
Feb 22, 2024
Published to the GitHub Advisory Database
Feb 22, 2024
Reviewed
Feb 22, 2024