CVE-2018-18942: Malicious File Upload
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/themeconfigs/form data[ThemeConfig][logo] parameter.
Other sources
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/themeconfigs/form data[ThemeConfig][logo] parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this baserCMS vulnerability?
The vulnerability ID of this baserCMS vulnerability is CVE-2018-18942.
What is the severity of CVE-2018-18942?
The severity of CVE-2018-18942 is high with a score of 7.2.
How can remote attackers exploit CVE-2018-18942?
Remote attackers can exploit CVE-2018-18942 by injecting arbitrary PHP code via the 'admin/theme_configs/form data[ThemeConfig][logo]' parameter.
Which versions of baserCMS are affected by CVE-2018-18942?
Versions of baserCMS before 4.1.4 are affected by CVE-2018-18942.
How can I fix the CVE-2018-18942 vulnerability in baserCMS?
To fix the CVE-2018-18942 vulnerability in baserCMS, update to version 4.1.4 or higher.