Impact
Stored Cross‑Site Scripting is present in baserCMS when strings are appended to email form fields without proper validation or escaping. Based on the description, it is inferred that the attack vector involves an attacker crafting an email that includes malicious script, which will be stored and later served to users viewing the email form. When a victim opens the affected page, the script executes in the victim’s browser, potentially stealing credentials, session cookies, or performing other client‑side attacks. This flaw falls under the identified weakness CWE‑79 and threatens confidentiality, integrity, and availability of user data within the application.
Affected Systems
The vulnerabilities affect the baserCMS platform distributed by User Community:baserCMS. No specific version range is listed, so all installations of baserCMS that use the email form feature remain at risk until a patch is applied.
Risk and Exploitability
With a CVSS score of 5.1, the flaw is considered moderate in severity. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting limited evidence of active exploitation. Based on the description, it is inferred that the attack vector requires an attacker to craft an email with malicious content and rely on the target system rendering it. The impact is limited to users who view the affected form, but the ability to drive arbitrary JavaScript in users’ browsers presents a significant threat.
OpenCVE Enrichment