CVE-2023-44379

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

18 Dec 2024, 16:54

Type Values Removed Values Added
References () https://basercms.net/security/JVN_73283159 - () https://basercms.net/security/JVN_73283159 - Vendor Advisory
References () https://github.com/baserproject/basercms/commit/18549396e5a9b8294306a54a876af164b0b57da4 - () https://github.com/baserproject/basercms/commit/18549396e5a9b8294306a54a876af164b0b57da4 - Patch
References () https://github.com/baserproject/basercms/security/advisories/GHSA-66c2-p8rh-qx87 - () https://github.com/baserproject/basercms/security/advisories/GHSA-66c2-p8rh-qx87 - Vendor Advisory
First Time Basercms
Basercms basercms
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

21 Nov 2024, 08:25

Type Values Removed Values Added
References () https://basercms.net/security/JVN_73283159 - () https://basercms.net/security/JVN_73283159 -
References () https://github.com/baserproject/basercms/commit/18549396e5a9b8294306a54a876af164b0b57da4 - () https://github.com/baserproject/basercms/commit/18549396e5a9b8294306a54a876af164b0b57da4 -
References () https://github.com/baserproject/basercms/security/advisories/GHSA-66c2-p8rh-qx87 - () https://github.com/baserproject/basercms/security/advisories/GHSA-66c2-p8rh-qx87 -
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.0.9, había una vulnerabilidad de cross site scripting en la función de búsqueda de sitios. La versión 5.0.9 contiene una solución para esta vulnerabilidad.

22 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 15:15

Updated : 2024-12-18 16:54


NVD link : CVE-2023-44379

Mitre link : CVE-2023-44379

CVE.ORG link : CVE-2023-44379


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')