VulnerabilityModified
CVE-2022-39325
In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS.
MEDIUM 6.1EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- basercms/basercms
- Source
- security-advisories@github.com
References
- https://basercms.net/security/JVN_53682526Vendor Advisory
- https://github.com/baserproject/basercms/commit/b6f8a54e90dee51317eddf517b776fe8b4cd3ef6Patch, Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-395x-wv32-44v5Third Party Advisory
- https://basercms.net/security/JVN_53682526Vendor Advisory
- https://github.com/baserproject/basercms/commit/b6f8a54e90dee51317eddf517b776fe8b4cd3ef6Patch, Third Party Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-395x-wv32-44v5Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.