PT-2026-79023 · Basercms · Basercms
CVE-2026-76635
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
baserCMS versions prior to 5.3.0
Description
An issue exists in
BcDatabaseService.php that allows authenticated administrators to inject controlled table names and configuration values into SQL statements during sequence update, CSV export, and table management operations. This can be combined with a backup restore code injection flaw, where PHP code located outside class definitions in schema files executes automatically upon loading. By chaining these flaws, an attacker can plant malicious table names to trigger error-based SQL injection, enabling the retrieval of the database version, schema contents, and arbitrary data from the PostgreSQL backend.Recommendations
Update baserCMS to version 5.3.0 or later.
Exploit
Fix
Code Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Basercms