CVE-2023-51450

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

18 Dec 2024, 16:55

Type Values Removed Values Added
First Time Basercms
Basercms basercms
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
References () https://basercms.net/security/JVN_09767360 - () https://basercms.net/security/JVN_09767360 - Broken Link
References () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - Patch
References () https://github.com/baserproject/basercms/security/advisories/GHSA-77fc-4cv5-hmfr - () https://github.com/baserproject/basercms/security/advisories/GHSA-77fc-4cv5-hmfr - Vendor Advisory

21 Nov 2024, 08:38

Type Values Removed Values Added
References () https://basercms.net/security/JVN_09767360 - () https://basercms.net/security/JVN_09767360 -
References () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c -
References () https://github.com/baserproject/basercms/security/advisories/GHSA-77fc-4cv5-hmfr - () https://github.com/baserproject/basercms/security/advisories/GHSA-77fc-4cv5-hmfr -
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.0.9, había una vulnerabilidad de inyección de comandos del sistema operativo en la función de búsqueda de sitios de baserCMS. La versión 5.0.9 contiene una solución para esta vulnerabilidad.

22 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 15:15

Updated : 2024-12-18 16:55


NVD link : CVE-2023-51450

Mitre link : CVE-2023-51450

CVE.ORG link : CVE-2023-51450


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')