baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-1429 baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
Github GHSA Github GHSA GHSA-fw5q-j9p4-3vxg Blog comment posting, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T13:15:19.024Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-30T19:15:12.707

Modified: 2024-11-21T05:05:15.057

Link: CVE-2020-15276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.