Loading HuntDB...

GHSA-24p5-x9f9-vvpx

GitHub Security Advisory

Cross-site Scripting (XSS) in baserCMS

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

Affected Packages

Packagist baserproject/basercms
Affected versions: 0 (fixed in 4.4.5)

Related CVEs

Key Information

GHSA ID
GHSA-24p5-x9f9-vvpx
Published
June 8, 2021 8:10 PM
Last Modified
July 5, 2023 11:17 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
baserproject/basercms
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.