CVE-2020-15154: Cross Site Scripting in baserCMS
Published Aug 28, 2020
·Updated
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: contentfields.php, contentinfo.php, contentoptions.php, contentrelated.php, indexlisttree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.
Affected Software
1 affected component
baserCMS BaserCMS<=4.3.6
Remediation
Patch Available
Event History
Aug 28, 2020
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for baserCMS?
The vulnerability ID for baserCMS is CVE-2020-15154.
2
What is the severity of CVE-2020-15154?
The severity of CVE-2020-15154 is high with a CVSS score of 7.3.
3
How does CVE-2020-15154 affect baserCMS?
CVE-2020-15154 affects baserCMS 4.3.6 and earlier versions.
4
How can CVE-2020-15154 be exploited?
To exploit CVE-2020-15154, admin access is required.
5
Are there any fixes or patches available for CVE-2020-15154?
It is recommended to update baserCMS to version 4.3.7 or later to fix CVE-2020-15154.