CVE-2021-20682

HIGH7.2EPSS 2.4%

OS Command Injection in baserCMS

Published: 6/8/2021Modified: 2/16/2024
Also known as:GHSA-g39q-f4rm-85x4

Description

baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via upload of malicious plugins.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (3)