Beveiligingsadvies

CVE-2020-15154

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-08-28 21:10:14
Laatst bijgewerkt 2024-08-04 13:08:22
Toegewezen door GitHub_M
CVSS-score 7.3
Status PUBLISHED

Beschrijving

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.