baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3. | |
| Title | baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T14:01:39.730Z
Reserved: 2026-01-05T16:44:16.367Z
Link: CVE-2026-21861
Updated: 2026-03-31T14:01:31.684Z
Status : Received
Published: 2026-03-31T01:16:35.540
Modified: 2026-03-31T15:16:12.020
Link: CVE-2026-21861
No data.
OpenCVE Enrichment
No data.