CVE-2023-25655: baserCMS allows any file to be uploaded
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25655?
The severity of CVE-2023-25655 is critical.
What is the affected software of CVE-2023-25655?
The affected software of CVE-2023-25655 is baserCMS version up to and excluding 4.7.5.
How can I fix CVE-2023-25655?
To fix CVE-2023-25655, you should upgrade to version 4.7.5 of baserCMS.
Where can I find more information about CVE-2023-25655?
You can find more information about CVE-2023-25655 at the following references: [link1](https://github.com/baserproject/basercms/commit/922025a98b0e697ab78f6a785a004e0729aa9100), [link2](https://github.com/baserproject/basercms/commit/9297629983ed908c7f51bf61a0231dde91404ebd), [link3](https://github.com/baserproject/basercms/releases/tag/basercms-4.7.5).
What is the CWE of CVE-2023-25655?
The CWE of CVE-2023-25655 is CWE-434.