CVE-2018-18942

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
05/11/2018
Last modified:
24/08/2020

Description

In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* 4.1.4 (excluding)