GHSA-4r3m-j6x5-48m3
GitHub Security Advisory
Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
Affected Packages
Packagist
baserproject/basercms
Affected versions:
4.0.0
(fixed in 4.3.7)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.