CVE-2022-39325 MEDIUM

CVE-2022-39325: Cross-site scripting vulnerability in BaserCMS

Vendor Baserproject
Product basercms
Weakness CWE-79 · XSS
Published November 25, 2022
Last update April 23, 2025

CVSS base score

4.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.

Key dates

02Disclosure timeline

November 25, 2022 CVE published
April 23, 2025 Record updated