CVE-2026-30877

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

01 Apr 2026, 20:28

Type Values Removed Values Added
First Time Basercms basercms
Basercms
References () https://basercms.net/security/JVN_20837860 - () https://basercms.net/security/JVN_20837860 - Vendor Advisory
References () https://github.com/baserproject/basercms/releases/tag/5.2.3 - () https://github.com/baserproject/basercms/releases/tag/5.2.3 - Release Notes
References () https://github.com/baserproject/basercms/security/advisories/GHSA-m9g7-rgfc-jcm7 - () https://github.com/baserproject/basercms/security/advisories/GHSA-m9g7-rgfc-jcm7 - Vendor Advisory
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.2.3, existe una vulnerabilidad de inyección de comandos del sistema operativo en la funcionalidad de actualización. Debido a este problema, un usuario autenticado con privilegios de administrador en baserCMS puede ejecutar comandos arbitrarios del sistema operativo en el servidor con los privilegios de la cuenta de usuario que ejecuta baserCMS. Este problema ha sido parcheado en la versión 5.2.3.

31 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 01:16

Updated : 2026-04-01 20:28


NVD link : CVE-2026-30877

Mitre link : CVE-2026-30877

CVE.ORG link : CVE-2026-30877


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')