Description

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.

INFO

Published Date :

2026-03-31T00:45:09.718Z

Last Modified :

2026-04-02T14:43:52.296Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30877 vulnerability.

Vendors Products
Basercms
  • Basercms
Baserproject
  • Basercms
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact