Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Akagi Yusuke

Researcher fromNTT-ME
#29531of 56,330
9.1Total CVSS
Vulnerabilities · 1
PT-2021-23208
9.1
2021-11-26
Basercms · Basercms · CVE-2021-41243
**Name of the Vulnerable Software and Affected Versions** baserCMS versions 4.5.3 and earlier **Description** The management system of baserCMS has a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This issue needs to be addressed when the management system is used by an unspecified number of users. **Recommendations** Update to the latest version of baserCMS. As a temporary workaround, consider restricting file upload permissions to minimize the risk of exploitation. Avoid using the file upload feature until the issue is resolved.