CVE-2023-43792: baserCMS Code Injection Vulnerability in Mail Form Feature
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
Other sources
There is a Code Injection Vulnerability in Mail Form to baserCMS.
Target baserCMS 4.7.6 and earlier versions
Vulnerability Malicious code may be executed in Mail Form Feature.
Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN45547161
Credits Shiga Takuma@BroadBand Security, Inc
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this code injection vulnerability in Mail Form to baserCMS?
The vulnerability ID for this code injection vulnerability in Mail Form to baserCMS is CVE-2023-43792.
What is the severity level of CVE-2023-43792?
The severity level of CVE-2023-43792 is medium, with a severity value of 5.3.
What is the affected software version for this vulnerability?
The affected software version for this vulnerability is baserCMS 4.7.6 and earlier versions.
How can I fix the code injection vulnerability in Mail Form to baserCMS?
To fix the code injection vulnerability in Mail Form to baserCMS, it is recommended to update to the latest version of baserCMS.
Where can I find more information about CVE-2023-43792?
You can find more information about CVE-2023-43792 on the following pages: [GitHub Advisory](https://github.com/baserproject/basercms/security/advisories/GHSA-vrm6-c878-fpq6), [baserCMS Security](https://basercms.net/security/JVN_45547161), [GitHub Advisory](https://github.com/advisories/GHSA-vrm6-c878-fpq6).