PT-2026-79023 · Basercms · Basercms

CVE-2026-76635

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions baserCMS versions prior to 5.3.0
Description An issue exists in BcDatabaseService.php that allows authenticated administrators to inject controlled table names and configuration values into SQL statements during sequence update, CSV export, and table management operations. This can be combined with a backup restore code injection flaw, where PHP code located outside class definitions in schema files executes automatically upon loading. By chaining these flaws, an attacker can plant malicious table names to trigger error-based SQL injection, enabling the retrieval of the database version, schema contents, and arbitrary data from the PostgreSQL backend.
Recommendations Update baserCMS to version 5.3.0 or later.

Exploit

Fix

Code Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76635
GHSA-CG65-F2M7-9FQJ

Affected Products

Basercms