Impact
An OS command injection flaw exists in the update feature of baserCMS. An authenticated administrator can trigger arbitrary operating‑system commands through the web interface, therefore obtaining full control over the host running the CMS. The attacker can execute commands with the privileges of the CMS process, enabling system compromise, data theft, or denial of service.
Affected Systems
The affected vendor is baserproject, product basercms. Versions prior to 5.2.3 are vulnerable. Version 5.2.3 and later contain the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, indicating a high severity. Exploit probability data is not available and the issue is not listed in the CISA KEV catalog. The likely attack path requires authenticated access with administrative rights; an attacker who can log in as an administrator can invoke arbitrary commands, making this a serious local privilege escalation that can lead to full system compromise.
OpenCVE Enrichment
Github GHSA