CVE-2024-46998: baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.
Other sources
XSS vulnerability in Edit Email Form Settings Feature to baserCMS.
Target baserCMS 5.1.1 and earlier versions
Vulnerability Malicious code may be executed in Edit Email Form Settings feature.
Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN00876083
Credits Ayato Shitomi@Fore-Z
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46998?
CVE-2024-46998 is classified as a cross-site scripting (XSS) vulnerability affecting baserCMS versions prior to 5.1.2.
How do I fix CVE-2024-46998?
To fix CVE-2024-46998, update your baserCMS installation to version 5.1.2 or later.
Which versions of baserCMS are affected by CVE-2024-46998?
CVE-2024-46998 affects baserCMS versions up to and including 5.1.1.
What feature is involved in CVE-2024-46998?
CVE-2024-46998 involves a cross-site scripting vulnerability in the Edit Email Form Settings feature.
Is there a secure version of baserCMS available for CVE-2024-46998?
Yes, baserCMS version 5.1.2 is the secure version that addresses the vulnerability related to CVE-2024-46998.