CVE-2024-46996: baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.
Other sources
XSS vulnerability in Blog posts feature to baserCMS.
Target baserCMS 5.1.1 and earlier versions
Vulnerability Malicious code may be executed in Blog posts feature.
Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN00876083
Credits Ayato Shitomi@Fore-Z
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46996?
CVE-2024-46996 is classified as a medium severity cross-site scripting vulnerability affecting baserCMS versions prior to 5.1.2.
How do I fix CVE-2024-46996?
To fix CVE-2024-46996, update baserCMS to version 5.1.2 or later.
What versions of baserCMS are vulnerable to CVE-2024-46996?
Versions of baserCMS prior to 5.1.2 are vulnerable to CVE-2024-46996.
What feature in baserCMS is affected by CVE-2024-46996?
CVE-2024-46996 affects the Blog posts feature of baserCMS.
Is CVE-2024-46996 a cross-site scripting vulnerability?
Yes, CVE-2024-46996 is a cross-site scripting (XSS) vulnerability.