CVE-2018-0575: Infoleak
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0575?
The severity of CVE-2018-0575 is medium with a CVSS score of 5.3.
How can remote attackers exploit CVE-2018-0575?
Remote attackers can exploit CVE-2018-0575 to bypass access restriction in mail form and view uploaded files.
Which versions of baserCMS are affected by CVE-2018-0575?
baserCMS versions up to 4.1.0.1 and 3.0.15 are affected by CVE-2018-0575.
How can I fix the vulnerability in baserCMS?
To fix this vulnerability in baserCMS, update to a version higher than 4.1.0.1 for baserCMS 4.x or higher than 3.0.15 for baserCMS 3.x.
Where can I find more information about CVE-2018-0575?
You can find more information about CVE-2018-0575 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-0575), [JVN](http://jvn.jp/en/jp/JVN67881316/index.html).