Vulnerability Description
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Basercms | Basercms | < 4.8.0 |
Related Weaknesses (CWE)
References
- https://basercms.net/security/JVN_24381990Vendor Advisory
- https://github.com/baserproject/basercms/commit/eb5977533d05db4f3bb03bd19630b660Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-ggj4-78rm-6xgvThird Party Advisory
- https://basercms.net/security/JVN_24381990Vendor Advisory
- https://github.com/baserproject/basercms/commit/eb5977533d05db4f3bb03bd19630b660Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-ggj4-78rm-6xgvThird Party Advisory
FAQ
What is CVE-2023-43647?
CVE-2023-43647 is a vulnerability with a CVSS score of 6.1 (MEDIUM). baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue...
How severe is CVE-2023-43647?
CVE-2023-43647 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43647?
Check the references section above for vendor advisories and patch information. Affected products include: Basercms Basercms.