CVE-2024-26128

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

20 Dec 2024, 19:30

Type Values Removed Values Added
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
First Time Basercms
Basercms basercms
References () https://basercms.net/security/JVN_73283159 - () https://basercms.net/security/JVN_73283159 - Vendor Advisory
References () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - () https://github.com/baserproject/basercms/commit/18f426d63e752b4d22c40e9ea8d1f6e692ef601c - Patch
References () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 - () https://github.com/baserproject/basercms/security/advisories/GHSA-jjxq-m8h3-4vw5 - Vendor Advisory

Information

Published : 2024-02-22 19:15

Updated : 2024-12-20 19:30


NVD link : CVE-2024-26128

Mitre link : CVE-2024-26128

CVE.ORG link : CVE-2024-26128


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')