CVE-2021-39136 HIGH

CVE-2021-39136: Cross-site scripting vulnerability in file upload

Vendor Baserproject
Product basercms
Weakness CWE-79 · XSS
Published August 25, 2021
Last update August 4, 2024

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.

Key dates

02Disclosure timeline

August 25, 2021 CVE published
August 4, 2024 Record updated

Related vulnerabilities

04Related CVE