CVE-2021-41243

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41243
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41243.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-41243
Aliases
Published
2021-11-26T18:15:07Z
Modified
2024-05-14T10:52:05.256861Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.

References

Affected packages

Git / github.com/baserproject/basercms

Affected ranges

Type
GIT
Repo
https://github.com/baserproject/basercms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

basercms-2.*

basercms-2.0.0
basercms-2.0.0-beta
basercms-2.0.1
basercms-2.0.2
basercms-2.0.3
basercms-2.0.4
basercms-2.0.5
basercms-2.0.5.1
basercms-2.1.0
basercms-2.1.1
basercms-2.1.2

basercms-3.*

basercms-3.0.0
basercms-3.0.1
basercms-3.0.10
basercms-3.0.11
basercms-3.0.11.1
basercms-3.0.2
basercms-3.0.3
basercms-3.0.4
basercms-3.0.5
basercms-3.0.5.1
basercms-3.0.6
basercms-3.0.6-beta
basercms-3.0.6.1
basercms-3.0.7
basercms-3.0.8
basercms-3.0.9

basercms-4.*

basercms-4.0.0
basercms-4.0.0-beta
basercms-4.0.1
basercms-4.0.10
basercms-4.0.10.1
basercms-4.0.11
basercms-4.0.2
basercms-4.0.2.1
basercms-4.0.3
basercms-4.0.4
basercms-4.0.5
basercms-4.0.5.1
basercms-4.0.5.2
basercms-4.0.6
basercms-4.0.7
basercms-4.0.8
basercms-4.0.9
basercms-4.1.0
basercms-4.1.0.1
basercms-4.1.1
basercms-4.1.2
basercms-4.1.3
basercms-4.1.4
basercms-4.1.5
basercms-4.1.6
basercms-4.1.7
basercms-4.1.8
basercms-4.2.0
basercms-4.2.1
basercms-4.2.2
basercms-4.2.3
basercms-4.2.4
basercms-4.2.5
basercms-4.3.0
basercms-4.3.1
basercms-4.3.2
basercms-4.3.3
basercms-4.3.4
basercms-4.3.5
basercms-4.3.6
basercms-4.3.7
basercms-4.3.7.1
basercms-4.4.0
basercms-4.4.1
basercms-4.4.1.1
basercms-4.4.2
basercms-4.4.2.1
basercms-4.4.3
basercms-4.4.4
basercms-4.4.5
basercms-4.4.6
basercms-4.4.7
basercms-4.4.8
basercms-4.5.0
basercms-4.5.1
basercms-4.5.2

bsercms-4.*

bsercms-4.4.4

Other

remove