baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baserproject
Baserproject basercms |
|
| Vendors & Products |
Baserproject
Baserproject basercms |
Thu, 02 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Basercms
Basercms basercms |
|
| CPEs | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Basercms
Basercms basercms |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3. | |
| Title | baserCMS: OS Command Injection in the baserCMS Update Functionality | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-02T14:43:52.296Z
Reserved: 2026-03-06T00:04:56.699Z
Link: CVE-2026-30877
Updated: 2026-04-02T14:43:45.847Z
Status : Analyzed
Published: 2026-03-31T01:16:35.830
Modified: 2026-04-01T20:28:43.797
Link: CVE-2026-30877
No data.