Impact
A CSV file injection flaw exists in BaserCMS. An attacker can craft a CSV file that contains malicious code. When a user downloads and opens the file with common spreadsheet software, the injected code may be executed, potentially allowing the attacker to run arbitrary commands on the victim’s machine.
Affected Systems
The vulnerability affects BaserCMS provided by the baserCMS Users Community. No specific product versions are listed in the advisory, so any installation at the time of discovery is potentially impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level. EPSS information is not available and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to entice a user to download and open a malicious CSV file, making the attack vector file-based and client‑side.
OpenCVE Enrichment