CVE-2024-26128

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

20 Dec 2024, 19:30

Type Values Removed Values Added
References () https://basercms.net/security/JVN_73283159 - () https://basercms.net/security/JVN_73283159 - Vendor Advisory
References () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - Patch
References () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 - () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 - Vendor Advisory
First Time Basercms
Basercms basercms
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

21 Nov 2024, 09:01

Type Values Removed Values Added
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.0.9, había una vulnerabilidad de cross site scripting en la función de administración de contenido. La versión 5.0.9 contiene una solución para esta vulnerabilidad.
References () https://basercms.net/security/JVN_73283159 - () https://basercms.net/security/JVN_73283159 -
References () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c -
References () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 - () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 -

22 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 19:15

Updated : 2024-12-20 19:30


NVD link : CVE-2024-26128

Mitre link : CVE-2024-26128

CVE.ORG link : CVE-2024-26128


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')