CVE-2011-2674: Medium severity basercms mail vulnerability
Published Oct 2, 2011
·Updated
BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.
Affected Software
25 affected componentsFixes available
composer/baserproject/basercms<1.6.12
1.6.12
baserCMS BaserCMS<=1.6.11.4
baserCMS BaserCMS=1.5.4
baserCMS BaserCMS=1.5.5
baserCMS BaserCMS=1.5.6
baserCMS BaserCMS=1.5.7
baserCMS BaserCMS=1.5.8
baserCMS BaserCMS=1.5.9
baserCMS BaserCMS=1.6.0
baserCMS BaserCMS=1.6.1
baserCMS BaserCMS=1.6.2
baserCMS BaserCMS=1.6.3
baserCMS BaserCMS=1.6.4
baserCMS BaserCMS=1.6.5
baserCMS BaserCMS=1.6.6
baserCMS BaserCMS=1.6.7
baserCMS BaserCMS=1.6.7.1
baserCMS BaserCMS=1.6.8
baserCMS BaserCMS=1.6.9
baserCMS BaserCMS=1.6.9.1
baserCMS BaserCMS=1.6.10
baserCMS BaserCMS=1.6.11
baserCMS BaserCMS=1.6.11.1
baserCMS BaserCMS=1.6.11.2
baserCMS BaserCMS=1.6.11.3
Event History
Oct 2, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-2674?
CVE-2011-2674 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2011-2674?
To fix CVE-2011-2674, upgrade to BaserCMS version 1.6.12 or a later version.
3
Who is affected by CVE-2011-2674?
Remote authenticated users of BaserCMS versions prior to 1.6.12 are affected by CVE-2011-2674.
4
What types of attacks can CVE-2011-2674 enable?
CVE-2011-2674 can enable unauthorized privilege escalation attacks.
5
Is there a known exploit for CVE-2011-2674?
There is no publicly disclosed exploit for CVE-2011-2674 reported in the wild.