CVE-2017-10844: Code Injection
Published Aug 28, 2017
·Updated
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
Affected Software
2 affected components
baserCMS BaserCMS>=3.0.0<=3.0.14
baserCMS BaserCMS>=4.0.0<=4.0.5
Remediation
Patch Available
Event History
Aug 28, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10844?
CVE-2017-10844 is considered high severity due to its capability to allow an attacker to execute arbitrary PHP code on the server.
2
How do I fix CVE-2017-10844?
To fix CVE-2017-10844, upgrade your baserCMS installation to version 3.0.15 or later, or 4.0.6 or later.
3
Which versions of baserCMS are affected by CVE-2017-10844?
CVE-2017-10844 affects baserCMS versions 3.0.14 and earlier as well as 4.0.5 and earlier.
4
What kind of attack is possible with CVE-2017-10844?
CVE-2017-10844 can allow attackers to execute arbitrary PHP code, potentially leading to complete server compromise.
5
Is there a workaround for CVE-2017-10844 if I cannot upgrade?
There are no known effective workarounds for CVE-2017-10844, and upgrading is the recommended course of action.