CVE-2026-97150: High severity baserCMS BaserCMS vulnerability
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an administrative user, as reflected by the required high privileges. The attacker must be able to cause a crafted baserCMS4-style addon to be processed by the addon conversion workflow.
What can a successful exploit do?
Because the migrator executes PHP contained in an addon's config.php during conversion, malicious code can perform arbitrary file read or deletion operations on the system using the administrative user's context.
What should administrators do until a fix is applied?
Do not convert untrusted or unreviewed baserCMS4-style addons. Inspect an addon's config.php before running the BcAddonMigrator conversion process, since that file is executed.