Edit feed settings and others, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0
Description
Reviewed
Nov 4, 2020
Published to the GitHub Advisory Database
Nov 4, 2020
Last updated
Jan 9, 2023
baserCMS 4.4.0 and earlier is affected by Cross Site Scripting (XSS).
Impact: XSS via Arbitrary script execution.
Attack vector is: Administrator must be logged in.
Components are: Edit feed settings, Edit widget area, Sub site new registration, New category registration
Tested baserCMS Version : 4.4.0 (Latest)
Affected baserCMS Version : 4.0.0 ~ 4.4.0
Patches : https://basercms.net/security/20201029
Found by Aquilao Null
References