CVE-2018-18942

HIGH7.2EPSS 0.93%

RCE in baserCMS before 4.1.4

Published: 5/13/2022Modified: 2/16/2024
Also known as:GHSA-rjc2-x53r-6c9r

Description

In baserCMS before 4.1.4, `lib\Baser\Model\ThemeConfig.php` allows remote attackers to execute arbitrary PHP code via the `admin/theme_configs/form data[ThemeConfig][logo]` parameter.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (4)