baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baserproject
Baserproject basercms |
|
| Vendors & Products |
Baserproject
Baserproject basercms |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Basercms
Basercms basercms |
|
| CPEs | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Basercms
Basercms basercms |
Tue, 31 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3. | |
| Title | baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T14:01:39.730Z
Reserved: 2026-01-05T16:44:16.367Z
Link: CVE-2026-21861
Updated: 2026-03-31T14:01:31.684Z
Status : Analyzed
Published: 2026-03-31T01:16:35.540
Modified: 2026-04-01T20:29:39.303
Link: CVE-2026-21861
No data.