CVE-2020-15155: Cross-Site Scripting in baserCMS
Published Aug 28, 2020
·Updated
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
Affected Software
1 affected component
baserCMS BaserCMS<=4.3.6
Remediation
Event History
Aug 28, 2020
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this baserCMS vulnerability?
The vulnerability ID for this baserCMS vulnerability is CVE-2020-15155.
2
What is the severity of CVE-2020-15155?
The severity of CVE-2020-15155 is high with a CVSS score of 7.3.
3
How does CVE-2020-15155 affect baserCMS?
CVE-2020-15155 affects baserCMS versions 4.3.6 and earlier and allows for Cross Site Scripting (XSS) via arbitrary script execution.
4
How can this vulnerability be exploited?
To exploit this vulnerability, admin access to baserCMS is required.
5
How can I fix CVE-2020-15155?
To fix CVE-2020-15155, you should update to version 4.3.7 of baserCMS where the issue has been fixed.