CVE-2025-32957: baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE)
Details The application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using requireonce without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included.
Vector: Malicious ZIP upload + insecure requireonce
PoC 1. Restore backup !image 1. Load file shell (insecure requireonce) !image !image
Impact Remote Code Execution (RCE)
Other sources
baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using requireonce without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included. This issue has been patched in version 5.2.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32957?
CVE-2025-32957 is considered a critical vulnerability due to its potential to allow remote code execution via unsafe file uploads.
How do I fix CVE-2025-32957?
To fix CVE-2025-32957, upgrade to baserCMS version 5.2.3 or later where the vulnerability has been addressed.
What is the nature of the vulnerability in CVE-2025-32957?
CVE-2025-32957 allows for a remote code execution attack through an unsafe file upload mechanism in the baserCMS restore function.
Are all versions of baserCMS vulnerable to CVE-2025-32957?
Yes, all versions of baserCMS prior to 5.2.3 are vulnerable to CVE-2025-32957.
What impact can CVE-2025-32957 have on my application?
CVE-2025-32957 can allow an attacker to execute arbitrary PHP code, potentially compromising the entire application and server.