CVE-2020-15276: Cross Site Scripting in baserCMS
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15276?
CVE-2020-15276 is a vulnerability in baserCMS before version 4.4.1 that allows for Cross-Site Scripting (XSS) attacks.
How does CVE-2020-15276 impact baserCMS?
CVE-2020-15276 allows an attacker to execute arbitrary JavaScript by entering a crafted nickname in blog comments.
What is the severity level of CVE-2020-15276?
The severity level of CVE-2020-15276 is high, with a severity value of 8.7.
How can I fix the CVE-2020-15276 vulnerability?
The CVE-2020-15276 vulnerability is fixed in version 4.4.1 of baserCMS. It is recommended to upgrade to this version to mitigate the issue.
Where can I find more information about CVE-2020-15276?
You can find more information about CVE-2020-15276 on the baserCMS security advisory page (https://basercms.net/security/20201029) and on the GitHub repository for baserCMS (https://github.com/baserproject/basercms/security/advisories/GHSA-fw5q-j9p4-3vxg).