VulnerabilityModified
CVE-2021-39136
In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS.
MEDIUM 5.4EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- basercms/basercms
- Source
- security-advisories@github.com
References
- http://jvn.jp/en/jp/JVN14134801/index.htmlThird Party Advisory
- https://basercms.net/security/JVN_14134801Vendor Advisory
- https://github.com/baserproject/basercms/commit/568d4cab5ba1cdee7bbf0133c676d02a98f6d7bcPatch, Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-hgjr-632x-qpp3Third Party Advisory
- http://jvn.jp/en/jp/JVN14134801/index.htmlThird Party Advisory
- https://basercms.net/security/JVN_14134801Vendor Advisory
- https://github.com/baserproject/basercms/commit/568d4cab5ba1cdee7bbf0133c676d02a98f6d7bcPatch, Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-hgjr-632x-qpp3Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.